Hacker News new | past | comments | ask | show | jobs | submit login

yikes, Gravatar has an open redirect.

http://www.gravatar.com/avatar/8ca7425c8ada807b9bf6934f10d59...

It's a fun trick, but it should't be possible.




Gravatar is designed that way so you can use any default image.

The technique is described in the Gravatar docs under "Default Image."

http://en.gravatar.com/site/implement/images/


Ah. But I'd expect think that they'd limit it to only images, or do some sorta safety checking. I recognize the performance concerns, but it's too easy to add a malware redirect onto their trusted url.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: