i was doing some research that brought me to page

https://longbows-hideout.appspot.com/popurls.com

not being familiar with popurls.com i thought the url was the actual home 
for it. liking what i was seeing i tried to log in to it via provided 
options as open id and google.

i noticed that both wrong and correct passwords were not getting 
acknowledged as either. the page would just refresh to blank.

poking around google links on all the pages prefixed with 
https://longbows-hideout.appspot.com i noticed broken links, bad formatting 
etc. as if the page was not real.

i noticed further that i can append pretty much any domain and get to it 
behind the firewall. i'm guessing this is someones proxy to go around their 
own restricted firewalls. it seems innocent enough.

my concern not knowing the scope and concept of appspot is, does anything i 
type into the fields of pages loaded though longbows-hideout go through 
that app for any sort of handling before it is passed along to the target 
site?
can it be potentially picked up? i.e. credentials harvested?


-- 
You received this message because you are subscribed to the Google Groups 
"Google App Engine" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
Visit this group at http://groups.google.com/group/google-appengine.
For more options, visit https://groups.google.com/groups/opt_out.

Reply via email to