https://google.com/amp/hackme.com
redirects to hackme.com. The attacker here used tiny.cc to be more elusive. IIRC we had a popular discussion here about this.
How google can still allow this is beyond me.
redirects to hackme.com. The attacker here used tiny.cc to be more elusive. IIRC we had a popular discussion here about this.
How google can still allow this is beyond me.
Whover allowed that in Google, using the main google.com domain, what was he thinking?
For me, that is the major story here.
It seems amp started as a whitelist of well-known publishers and morphed into somthing like an open proxy.
But if I understood correctly it started from the idea "Google hosts your pages (if I understand correctly, even the scripts!) now with Google's TLS certificate and on Google's www.google.com domain" which is also quite fracked up for what can be expected of www.google.com?