Tuesday, October 4, 2005
These all work (I'm using underscores instead of spaces to maintain clickable links on this page, but almost any characters work, including spaces) :-

And for the other Google services too.

Is this oddity known about? am I the last to notice? Is it a Google quirk or a more general web server quirk?

Anything useful or dangerous about it?

Here's a half-hearted phishing-like URL, where it's made to look like the search term is one thing [spoofed_word] but in fact it's another [oddity]. A *lot* more underscores can be used to push the latter part of the URL out of sight, but I've kept the example fairly short. Spaces (or periods, etc) work fine instead of underscores too :-

Here's a way of sharing a search URL, whilst retaining 'credit' and/or a reminder of it's source :-

Or even :-[Sponsored_by____http://www.iMilly.com____Your_Premier_Source_of_High_Class_Spondoolics!!___]/search?q=oddity

And of course that type of URL construction could easily be built into the morass of browser Toolbars, or even the search tools bundled with the browsers themselves.

I hate to imagine what the SEO spammers might do with such subverted Google search URLs.

I suppose it might be combined with My Search History spam too (see :-

And bloggers sometimes like to (and Bloggers must) use Google's redirector like so :-

But this works too[1] :-

Ooh er, what might I have unleashed ...

Any other wrinkles?


[1] Though the redirector has always been susceptible to padding in this form anyway :-

As for the multi-slashes, as far as I know that's normal server behavior. It works on my Apache as well: try

Interesting spoof URLs you found there.

Hmm, yes, but on any of these, say, you're serving up an "HTTP/1.1 404 Not Found" response :-

I suppose that's what Google ought to be doing?

(I'm don't know much about server setups, by any means).

