Baidu qiba URL jump can be used for phishing
Baidu qiba URL jump can be used for phishing
Problem URL: http://ssp.baidu.com//ce.wooyun.org
Http://ssp.baidu.com> http://ssp.baidu.com/home
That is to say, directly open the http://ssp.baidu.com, the website will jump to the/home page, but the HOST value is obtained from the last // instead of the first //
So as long as the http://ssp.baidu.com plus // and then add any site can jump, of course, the premise of normal open is to jump to the site to have/home this page
HTTP/1.1 302 Found
Connection: Keep-AliveContent-Length: 0 Date: Wed, 23 Sep 2015 12:26:48 GMTLocation: http://ce.wooyun.org/homeServer: Apache-Coyote/1.1Set-Cookie: ses_cache _ cas _ st __= workshop; domain = ssp.baidu.com; Path =/X-Cf-Requestid: 58bb2a7a-3e68-4626-707e-45c5abc81a37X-Prism-Spanid: 0X-Prism-Uid: plain: text/plain; charset = UTF-8
Can be used for black market phishing
Solution:
Bind HOST to jump directly