This is much worse, this is a redirect after login. You just logged into google, you entered your 2FA code, and then the next site you arrive at you damn well expect to be google.
Additionally, the OP is correct in that there is a whitelist bypass happening here. Why bother to whitelist *.google.com/ if you can bypass it with a redirect.
Actually, if it is an untrusted URL, I'm not sure why I'd expect that.
Here is the demonstration url from the report https://accounts.google.com/ServiceLogin?service=mail&contin...
My point isn't about 'open redirects' not being a security issue, it's that the report should be valid because it's a whitelist bypass.
continue=yahoo.com is blocked but continue=https://www.google.com/amp/yahoo.com is not blocked.
both do the same thing as far as the end user is concerned.
My guess is that posting this thing on HN has caused them to fix it.
OR maybe I'm being phished.
That's not really true though. Google serves as an identity provider providing login into 3rd party websites. Plus there's also OAuth prompts when 3rd party services want to use your Google data.
If it's again asking for a password, it must be Google.
https://mobile.twitter.com/taviso/status/769391927892598784
Edit: this one is better
I hadn't considered login redirects. This attack vector is one I can see myself falling for. Sign in on the legitimate google.com domain. Whoops, I just mistyped my Google password - not a rare occurrence. An exact replica of the "incorrect password" page has me type in my password again. Then they have a replica of the two-step authentication screen. I enter in the valid TOTP code, and now I've just given a third-party full access to my Google account.
This should absolutely be considered a serious threat. Hell, the only thing we freaking teach non-tech-savvy people to do is to look at the domain name. This attack vector completely bypasses that common understanding of how to detect phishing. There is absolutely no way I should land on a 3rd party domain after authenticating, without at least an interstitial page informing me I am heading off of Google's properties. Any redirect chain specifically from login should require landing on a Google domain, or have an interstitial. This doesn't need to be done globally for all redirects - just from login.
Oh well, I learned something new today. Re-check the domain you are on every time you type in credentials. You can't rely on your initial entry page being on the right domain, you have to be paranoid to the point of insanity every time you touch your keyboard.
If people ever send you Google Docs links, you're likely vulnerable unless you are as vigilant on the "Wrong Password" page as you were on the initial one.
Stringing together multiple (seemingly) insignificant vulnerabilities to pivot through a system or own a user is hacking 101. I'm not sure how you'd fix this, but given Google's prevalence as an authentication provider, it's definitely not worth being glib about.
(link removed, see video below)
And tell me your parents/grandparents/etc will not mistake that for the real thing.
(you can enter whatever you want into the phishing form, it will just take you back to this post – but someone with less morals could do entirely different things)
EDIT: Video for mobile users (this page doesn’t work on mobile): https://cdn.kuschku.de/ServiceLogin/video.mp4
If you now also register something like accountsgoogle.com or a similar page, people likely wouldn’t even notice.
This is like it’s made for phishing.
One of the reasons why I hate automated systems judging things.
Thanks, Google...
If it is an example, which is non-malicious, and even says "Don’t enter your password", and doesn’t even store the data from the input fields, it’s not.
It could easily check if any JS is executed, or if the form fields ever get sent anywhere (both is not the case).
Turns out I was wrong.
Google is facilitating phishing with this terrible behavior. It means that someone trying to phish a Google user can send someone to a totally valid google.com URL and it will still result in their credentials being stolen. That's the #1 thing that you teach non-technical people to avoid phishing; "Make sure the site you're on is the one you think you're logging into."
Because Google has chosen to be sloppy and dumb that simple instruction is not enough to protect people.
Google is 100% wrong here. This is a blatant hole and just a lazy, sloppy stupid, way too broad whitelist.