On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

June 3rd, 2007

Google services still have many security holes

Posted by Garett Rogers @ 10:10 am

Categories: Gmail, Google Webmasters

Tags: Desktop, Security, Google Inc., Google Gmail, Google Desktop, Attacker, Attack, Garett Rogers

The Register reports that there have been several security vulnerabilities discovered by determined attackers over the past week — these range from a hole in Google Desktop that lets a malicious attacker execute any file on a users computer to an XSS vulnerability in Gmail letting an attacker access or delete a users email.

The person who discovered the Google Desktop vulnerability posted the details of this attack here — it is a man in the middle (MITM) attack injecting code that forces a user to click on a “Google Desktop result”.

An XSS attack on Gmail was also discovered this week — in my opinion, it is actually a bit more serious than the Google Desktop one. An attacker could hijack your Gmail session by getting you to visit a malicious website. Fortunately Google promptly fixed this one after it was posted.

The most interesting hole discovered this week though was found in a tool that webmasters can use to request removal of pages. Anyone could traverse up the directory tree to see files on Google’s servers that should be hidden from view. For example, 0×000000 was able to find a root password for one of Google’s databases by simply downloading a file — woops!

Garett RogersGarett Rogers is employed as a programmer for iQmetrix, which specializes in retail management software for the wireless industry. See his full profile and disclosure of his industry affiliations.


Email Garett Rogers

Subscribe to Googling Google via Email alerts or RSS.

  • Talkback
  • Most Recent of 3 Talkback(s)
Holes and false positives
It's also become apparent recently that Google Groups is suffering from a problem with spammers and other assorted malcontents and goodness knows how much malware is floating around.

While all ... (Read the rest)
Posted by: TtfnJohn Posted on: 06/04/07 You are currently: a Guest | | Terms of Use
about the desktop and toolbar one  Ratatosk | 06/03/07
XSS everywhere? use NoScript  Prophet Elias | 06/04/07
Holes and false positives  TtfnJohn | 06/04/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline