New issue
Advanced search Search tips

Issue 716985 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: foreign link disguised as google search went undetected

Reported by sti...@gmail.com, May 1 2017

Issue description

VULNERABILITY DETAILS
Foreign link disguised as google search link went undetected.

VERSION
Version 58.0.3029.81 (64-bit)
Operating System: Win 10 home 64 bit 

REPRODUCTION CASE
If you copy-paste this URL:

https://www.google.com/url?sa=t&url=%68%74%74%70%3A%2F%2F%65%79%74%79%2E%72%75&usg=AFQjCNFt5Ygu2XIToaTq4JaZejScRlmatQ

You will end up at some credit card fraud website instead of what appears to be a google search.

I tried changing the URLencoded url (to bing.com) and I tried omitting the usg parameter. In both those cases, chrome will detected the redirect and ask me to confirm, showing me the actual link. Which is the desired behaviour. But for me, this URL as I pasted it here managed to skip that screen. I received the link via a typical skype spam virus.
 
Status: WontFix (was: Unconfirmed)
The complaint here is that Google.com is hosting an open-redirector. This is an issue in Google.com, not in Chrome.

Typically, the way to report these would be via the Google Vulnerability rewards program, but the Google.com team considers open redirectors out-of-scope: https://sites.google.com/site/bughunteruniversity/nonvuln/open-redirect

While I'm not an expert on this, my assumption is that the USG argument is a signed hash of the url argument, so that if you change either, the redirect system recognizes that the URL has been altered and prompts for confirmation.
Project Member

Comment 2 by sheriffbot@chromium.org, Aug 8 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment