Google hijacking 404 error pages
seoker.com
seoker.com
Worked great in FF but totally broke in IE7. Why? Because the 404 page size was under 1Kb, IE7 decided that our 404 page wasn't informative enough and supplied it's own.
The solution, as stupid as it sounds was to add enough white space to the file until it was larger than 1Kb.
And, you know, also stop sending broken links out.
http://www.google.com/support/toolbar/bin/answer.py?hl=en...
Anyway, if you're having this issue, you probably agreed on this behavior when you accepted their license :-).
However, for people who like to put sensitive user data in GET variables (coughMonstercough), this is yet another reason why they shouldn't do that.
It will likely result in incidences where support staff have a checklist of "do you have the Google Toolbar installed? Uninstall it first." However, I don't imagine there will be a ton of cases like this.
I do think it is a mistake that the Google Toolbar enables this by default. Taking this power away from the website owners is not good. And let's be honest, At least 50% of people who have the toolbar installed are not technically savvy and a good portion of them probably didn't even intend to install the software (it was bundled with another download, etc).
Also, I don't see a problem with the practice of putting sensitive data in GET variables if the website is protected by SSL - Am I missing something? Edit: Thanks for the reply aaco, those are both valid reasons and I appreciate the insight.
1. When downloading other software, I have seen several instances where the Google toolbar is bundled, and you have to go into an advanced menu to de-select it. 2. Many OEMs are now shipping computers to people with the Google Toolbar installed.
I believe these two cases account for a large number of the installs. Possibly even greater than the number of users who intentionally go out and download it, but more likely in the 30% range of new installs.
Of course, I have no real numbers on this, and so it is pretty much a guess.
GET requests are logged by the web server and in the browser history in plain text, even for SSL requests.
Therefore any server administrator or computer user can have access to those information just reading the server log or the browser history.
Here is my original write up of the creeps... http://blog.eznet.frih.net/?p=62
Here is Charters hi-jack http://www11.charter.net/search?qo=asdasd.asd&rn=3RjeJZ7...
Here's the post that convinced me to try it out: http://www.fourhourworkweek.com/blog/2007/12/28/12-filtering...