When Marketo Nation became publicly accessible last month, something pretty bad came along with that otherwise positive move: phishers can now use the Nation in attacks, by bouncing off /external-link.jsp (http://nation.marketo.com/external-link.jspa?url={{my malicious link here}}). This was possible in the past as well, but only if someone was logged into the Nation, which reduced the attack surface considerably.
By coincidence (well, maybe not, given the state of the world) I was just working on a blog post about a major firewall/VPN platform that has the same vulnerability.
The solution is that Jive must only redirect to URLs that were originally entered by authenticated users. Let's not be part of the problem!
P.S. If anyone wonders why those pesky mail scanners that mess with click tracking are necessary, this is why!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.