Google Blogoscoped

Forum

Google News used to fake referer/phishing

Corsin Camichel [PersonRank 10]

Tuesday, May 2, 2006
18 years ago2,796 views

I just noticed something:
You can use Google News (Germany confirmed, others likely to do the same) to fake/hide the referer.

Proof:
http://news.google.de/news/url?sa=T&ct=de/0-0&fd=R&url=http://blogoscoped.com/google-blog.html&cid=0&ei=IoxXRJOdFYKuoQLo0oz8BA
Now, in the Server log, as referer you have news.google.de.
This can of course be used for pishing.

I know, this is not the proper way to publish "security holes", but I lost my password for the BugTraq/SecurityFocus/Full-disclosure mailinglist :o)

Forum home

Advertisement

 
Blog  |  Forum     more >> Archive | Feed | Google's blogs | About
Advertisement

 

This site unofficially covers Google™ and more with some rights reserved. Join our forum!