New issue
Advanced search Search tips

Issue 821278 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 821282
Owner: ----
Closed: Jul 5
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: ----



Sign in to add a comment

Open redirection

Reported by jishnu.p...@gmail.com, Mar 13 2018

Issue description

Attack scenario:
Google Chrome is one of the most popular browser in the world..Chrome has a lot of advantages, it prevents most of the XSS attacks..but here i describe a open redirection vulnerability in chrome..an attacker can redirect any website by putting just an @anotherdomain.com symbol at end of the domain.. 
eg: https://www.facebook.com@youtube.com , then it will be directly redirect to youtube.com.therfore an attacker can inject malicious code and rediect any website directly using Chrome..but if we put @anotherdomain.com symbol in other browsers it will pop-up a dialogue box to user's to take decisions that is they want to redirect or not..but chrome does'nt pop-up a dialgoue box...it will directly redirect..
Browser/OS: Google Chrome/Windows 

Steps to reproduce:
  
Open Google Chrome,then search anything we want...here i open facebook.. https://www.facebook.com, then type @anotherdomain.com for eg: https://www.facebook.com@youtube.com

Then it will directly redirected to youtube without any warning..but most of the other browsers pop-up a dialogue box to prevent the redirect 

I included a video(poc) to reproduce the issue. I uploaded the poc video in my google drive and the google drive link is

 https://drive.google.com/open?id=148ucXkUsYbyZQlHb5F_5LaIiLmsqIPtZ
 
Mergedinto: 821282
Status: Duplicate (was: Untriaged)
Marking as duplicate as the bug was filed twice

Sign in to add a comment