Web Hack List

Collected research

The unexpected Google wide domain check bypass

A URL-parsing regex used across Google products ended the authority only at slash, question mark or hash, while browsers also end it at a backslash. A host written as attacker.tld then a backslash then something.corp.google.com passed an ends-with whitelist while the browser kept the attacker origin, so an embedded console iframe posted the victim's API key to the attacker.

Record

Researcher
David Schütz and @xdavidhu
Published by
bugs.xdavidhu.me
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of David Schütz and @xdavidhu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .