Monday, November 4, 2024
HomeVulnerabilityBeware!! Google Map Vulnerability Allows an Attacker to Redirect Victims into Malicious...

Beware!! Google Map Vulnerability Allows an Attacker to Redirect Victims into Malicious Websites

Published on

Malware protection

An open redirection vulnerability in Google Map lets allows hackers redirect victims into malicious websites that leads to downloaded malware and other potential threats.

Attackers Abuse Google’s goo.gl URL shortening service and hide the pernicious URL within it to trick victims and redirect to visit malicious web pages.

Since URL shortens work by sending the user browsers via at least one HTTP redirect that obviously helps an attacker to hide the scamming and phishing URL but Google intelligence always check the spammy URL almost as easy to report as they are to create.

- Advertisement - SIEM as a Service

In this case, Hackers are performing another HTTP redirection after the goo.gl redirection but this time attackers redirect into the legitimate website but its actually compromised by them.

According to Researcher, With a little help from,curl -I I followed the chain of URL redirects to see where I’d end up.

“There were two redirections in the chain before the final you-wouldn’t-click-it-if-you-saw-it Russian URL hosting an English language scam. The scam was the usual breathless guff and faux endorsements – in this case lies about the folks on Shark Tank – trying very, very hard to convince me that a turmeric diet pill can overcome my daily efforts to eat all the biscuits.”

Middle of the Redirect Chain Google Map Vulnerability

Interesting Part in this case, Middle of the redirect chain in between Shorten URL service and end of the Scam page.

Between the legitimate Google URL shortened you’d probably trust, and the Russian URL you probably wouldn’t, the redirection chain bounces you through another Google URL belonging to Google Maps.

An open Redirection vulnerability in Google Map service maps.app.goo.gl. allow lets attacker used it along with a service designed for shortening and malicious links were shared through Google Maps.

“Open redirect vulnerabilities allow attackers to abuse code that’s intended to perform an HTTP redirect to a specific something into code that redirects to anything.”

Ex: https://maps.app.goo.gl/?link=https%3A%2F%2Fexample.org

According to Naked Security Researcher, to avoid being abused, code that performs redirections should only send users to URLs that match a specific pattern or list of links thought to be OK.

In the case of Google maps that should be simple – if the URL in the link parameter isn’t a Google Map, there’s no reason to allow the redirection.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

LightSpy iOS Malware Enhanced with 28 New Destructive Plugins

The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS...

ATPC Cyber Forum to Focus on Next Generation Cybersecurity and Artificial Intelligence Issues

White House National Cyber Director, CEOs, Key Financial Services Companies, Congressional and Executive Branch...

New PySilon RAT Abusing Discord Platform to Maintain Persistence

Cybersecurity experts have identified a new Remote Access Trojan (RAT) named PySilon. This Trojan...

Konni APT Hackers Attacking Organizations with New Spear-Phishing Tactics

The notorious Konni Advanced Persistent Threat (APT) group has intensified its cyber assault on...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Google Chrome Security, Critical Vulnerabilities Patched

Google has updated its Chrome browser, addressing critical vulnerabilities that posed potential risks to...

New Windows Downgrade Attack Let Hackers Downgrade Patched Systems To Exploits

The researcher discovered a vulnerability in the Windows Update process that allowed them to...

Hackers Use Fog Ransomware To Attack SonicWall VPNs And Breach Corporate Networks

Recent cyberattacks involving Akira and Fog threat actors have targeted various industries, exploiting a...