Google Groups Home
Help | Sign in
Message from discussion Google XSS Exploit
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Reelix  
View profile
 More options May 16, 11:57 pm
From: Reelix
Date: Fri, 16 May 2008 06:57:22 -0700 (PDT)
Local: Fri, May 16 2008 11:57 pm
Subject: Google XSS Exploit
Greetings.

I recently got a GMail Spam Message that was rather unique from the
others...

This is because this one exploited a google XSS Hole...

A Proof-Of-Concept link is as follows

http://www.google.com/pagead/iclk?sa=l&ai=DdCosjy&num=10388&adurl=htt...

The above link, although starting with www.google.com, takes you
instead to http://www.gmail.com/

In the Proof-Of-Concept link, the end (adurl=http://www.gmail.com/)
can be changed to any website whatsoever...

Eg:

http://www.google.com/pagead/iclk?sa=l&ai=DdCosjy&num=10388&adurl=htt...

for my website.

I think someone should take a look into this...

- Reelix


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2008 Google