Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Phish could be this:

$inane_marketing_trope

...

Click here to Unsubscribe from Bluesky

https://porcini.us-east.host.bsky.network/xrpc/com.atproto.s...

...

Redirects to bad site.



As long as content is authored by the administrator of the server, I don't see where there is a security issue.

It's like if you point to your own Apache server in your own domain where you host a scam page and say there's a security issue with Apache because you could do that.

Or are you saying that you can make this person's server serve third-party content?


> Or are you saying that you can make this person's server serve third-party content?

Http: yes see OP

Email: not sure. Hopefully not. But spoofing happens.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: