Open Redirect On Google.com

Summary

Actually this open redirect is from appengine.google.com, but i combine it with google.com

Step To Reproduce

https://www.google.com/accounts/Logout?continue=https://appengine.google.com/_ah/logout?continue=https://www.evil.com

Explain

Open redirect found on appengine.google.com, and i combine it with google.com , because this is subdomain google also, so the google trust the subdomain and redirect it.

But, sadly this is not getting bounty, i dont know why, but I after read on someone blog, he is also report this bug, and google dont qualify this to bug. you can more read the explain from his blog on : http://vagmour.eu/google-open-url-redirection/

he is better than me, Zuahahaha...

Thanks,
Apapedulimu

Comments

  1. There's nothing buying bounty, I just don't discover for what reason, and yet I just subsequent to read on Redirect Http to Https a professional blog page, he will even state this unique parasite, not to mention search engine don't are considered this unique towards parasite. you can actually further read the discussion because of your partner's blog page concerning.

    ReplyDelete

Post a Comment

Popular posts from this blog

Missing CSRF Token On Add Admin [Popoji CMS]

Open Redirect On Codepolitan.com

Session not expired When logout [partners.uber.com]