Open redirect flaw in Facebook & Google Allows Phishing, Spam & More
Here's a nasty little Null Byte. An open redirect vulnerability was found in both Facebook and Google that could allow hackers to steal user credentials via phishing. This also potentially allows redirects to malicious sites that exploit other vulnerabilities in your OS or browser. This could even get your computer flooded with spam, and these holes have been known about for over a month.
Normally, holes like this are fixed within a few hours, but Google and Facebook don't seem to care too much. Google does not offer their regular Vulnerability Reward for this kind of exploit. So, we will be going over how this exploit could be used against us and how to protect ourselves from it. Maybe this will encourage Google and Facebook to push their developers into fixing these holes as soon as possible. I wish it wouldn't take a few thousand user complaints to get them motivated.