Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Fixes and Improvements

February 15th, 2013, 12:11 GMT · By

Moroccan Expert Finds “Unmonitored” Open Redirect Vulnerability in Google

SHARE:

Adjust text size:

Open redirect vulnerability identified in Google
Enlarge picture
Moroccan security researcher Abdelmorite Eljoaydi, aka Jigsaw, has identified an open redirect vulnerability that affects Google.

The expert has told Softpedia that the vulnerability is different from other open redirect issues identified in Google services.

“The vulnerability that I have found recently is an unmonitored redirection,” Eljoaydi explained.

“The phisher in this case can handle the validation hash value and control the redirect to his website – which includes malware, scams, etc – and use it for bad purposes by doing a simple trace of his website on Google search engine and replacing the hash value after the parameter ‘&usg={Specified hash}’.”

He has found that an attacker can use the method to bypass Google’s security checks and take advantage of the site’s functionality because “the destination parameters can’t be avoided, and the supplied hash value is static for each website, and authorized for the user.”

“Every time phishing attempts have a more trustworthy appearance. And in this case we are face to face with what we call in the security world, [URL Redirection]. The important part is that when an attacker can control the redirect location, they can exploit it for nefarious purposes - usually this means spam or phishing attacks,” the researcher added.

Moreover, cybercriminals can use resort to obfuscation techniques to ensure that the malicious links don’t raise any suspicion.

Eljoaydi has notified Google about his findings. However, the company believes that “the usability and security benefits of a well-implemented and carefully monitored URL redirector tend to outweigh the perceived risks.”

Google has been notified on several occasions about such vulnerabilities, but each time the response was pretty much the same.

Additional technical details of the vulnerability, the risks posed by it, and some suggestions on how the issue can be addressed are available here.


1,515 hits · 2 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


NIST and DHS's NPPD Sign Agreement on Cybersecurity

Largest Percentage of 2012 Cyberattacks Originated in Romania, Study Finds

Two DOM-Based XSS Vulnerabilities Addressed by Booking.com

Cybercriminals Exploit Microsoft Office Flaws to Attack Uyghur Mac Users

Flash Player 11.6 Addresses Multiple Buffer Overflow Vulnerabilities

READER COMMENTS:


Comment #1 by: MOURAD on 15 Feb 2013, 22:37 UTC reply to this comment

Moroccans are really extremely advanced in computing just just helped Microsoft to detect some map functioning in their MSN as-well so my advice to google in Kirkland Washington state to start hiring moroccans no joke.
Microsoft also needs to hire moroccans good peoples smart and funny.


Comment #2 by: Alphateam on 20 Feb 2013, 02:25 UTC reply to this comment

Moroccans are the best in cyber computing.
Moroccans are the best no joke just have a contest bring anyone you may have as best vs a moroccan tech you will see a big deference.
We have an advance military systems that we use to teach our civilian students.
One moroccan civilian tech is equivalent to agent in a intelligent service no joke.
Just do a world contest you will see.
No foreign governments has challenge us before ask your self why?
USA's best defense against Chinese hackers is moroccans.

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM