Secret phishing bug google dont want you to know

4 months ago 49
BOOK THIS SPACE FOR AD
ARTICLE AD

Eyaalgabay

RTLO Injection in gmail

Go to below link:

https://www.google.com/search?q=1234%E2%80%AE5678

You will see that google is looking for “12348765” but why? and what is the value in the middle?

Answer:

The charecter in the middle is RTLO (\u202e) character which tell the UI to present all charecter from right to left from now on.

While google search is good example to explain RTLO Gmail is good place to show how it can be abused.

Below image is an example of what hacker may send:

It look like a regular email but never did they know that the first char is RTLO and the real link is:

https://attacker.com/=e?moc.elgoog.yap//:sptth

Example of the victim point of view:

Read Entire Article