Web Hack List

Collected research

URL Spoofing vulnerability in bots of search engines

[WEB SECURITY] URL Spoofing vulnerability in bots of search engines

URL spoofing using space characters: http://www.site.com%20www.site2.com displays the first host in the address bar but loads the second. GoogleBot and Yahoo! Slurp index such addresses and Mozilla 1.7.x and IE6 follow them; Mozilla errors above 19 spaces while IE accepts more. Usable for phishing, malware distribution and keyword stuffing.

Record

Document
[WEB SECURITY] URL Spoofing vulnerability in bots of search engines
Researcher
MustLive
Published by
webappsec.org
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of MustLive, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .