Live data from Hacker News

Open redirects – a vulnerability class no one but attackers cares about

stevetabernacle.github.io

41–43 of 43 posts

Re: Open redirects – a vulnerability class no one but attackers cares about

#41
post #33

Open redirects are also used to prevent referrers from propagating through. In that sense, they're very useful for anonymisation.

there are many browser extensions to spoof or disable your referrer

The point is for the site owner to prevent it from showing up in the referer logs of other sites, regardless of browser.

Re: Open redirects – a vulnerability class no one but attackers cares about

#42
post #21

Earlier quoted context omitted.

That might not be an issue for Google, but I could see it being a big problem for a company that relies heavily on projecting a "family friendly" image (think Disney).

Back in the day you could change some URL parameters and make it look like Toys R Us was selling firearms on their website because they used the same ecommerce back end as a sporting goods store. Like you'd go to the URL and it would be a hunting rifle (or whatever) but it would be on the Toys R Us site. I don't think Toys R Us was ever harmed but it was mildly amusing and I'm sure a few people's panties got knotted…

I hadn't heard of this issue specifically, but it sounds like you may be talking about eBay Enterprise[1]. They ran a lot of e-commerce operations for brick and mortar stores at one point, including both Toys R Us and Dick's Sporting Goods.

[1] https://en.wikipedia.org/wiki/EBay_Enterprise

Re: Open redirects – a vulnerability class no one but attackers cares about

#43
post #33

Earlier quoted context omitted.

there are many browser extensions to spoof or disable your referrer

The point is for the site owner to prevent it from showing up in the referer logs of other sites, regardless of browser.

I wish every site would do that... but they like to do the opposite
Post reply on HN