Web Hack List

Other nomination

The unexpected Google wide domain check bypass

A URL-parsing regex used across Google products ended the authority only at slash, question mark or hash, while browsers also end it at a backslash. A host written as attacker.tld then a backslash then something.corp.google.com passed an ends-with whitelist while the browser kept the attacker origin, so an embedded console iframe posted the victim's API key to the attacker.

Record

Researcher
David Schütz and @xdavidhu

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of David Schütz and @xdavidhu, first published at the original source. Preserved copies are kept so the citation survives its host.