Phishing takes advantage of Google Search's site redirection feature
A new phishing campaign takes advantage of the ability to easily redirect Google Search web addresses to users.
Users will not doubt when clicking on links with Google domain. Security researchers come across phishing URLs that appear to be trustworthy and point to Google.
However, when analyzing these URLs, it is revealed that hackers have appended the parameters to automatically open HTTP redirection of Google Search. In this way, scammers try to redirect users to fraudulent, malicious websites.
In a recent blog post, Sophos revealed the URL format that appends to Google Search's open redirect parameters:
https://www.google.com/url?sa=t&url=[redacted]&usg=[redacted]
First, the URL looks reliable because it adds a link to Google. Experts often warn users to beware of suspicious links. But in this case, the user doesn't find anything malicious because the destination address is directed to Google. So users still click and ignore security warnings, and this is a security challenge. A few years ago, crooks also abused open navigation holes in Google Maps.
Taking advantage of Google's redirects to cheat
Security researchers also said Google does not consider open redirects to be a security issue. You may need a few notes below to ensure your safety when using the internet:
4 ★ | 4 Vote
Read More
- New phishing attacks appear to use Google Translate as a disguise
- Google discovers over 18 million Covid-19 phishing emails per day
- How to block phishing attacks in Firefox 3
- Page navigation (Redirect) in JavaScript
- Beware of a trick that takes advantage of Google Wave
- Warning: Microsoft and Google Clouds are being abused to launch large-scale phishing campaigns
- What is Spear Phishing?
- How to enable Site Isolation security feature on Chrome