On GameSpot: Courtney Love to sue over Guitar Hero 5
BNET Business Network:
BNET
TechRepublic
ZDNet

December 19th, 2007

Notebook: Google Toolbar flaw; Gmail issues; Microsoft assessment tool

Posted by Larry Dignan @ 4:19 am

Categories: Google, Hackers, Microsoft, Uncategorized, Vulnerability research

Tags: Google Toolbar, Google Inc., Google Gmail, Notebook, Vulnerability, Toolbar, Cenzic Inc., Microsoft Corp., Tool, Flaw

A roundup of a few security odds and ends over the last two days.

Unpatched Google Toolbar flaw presents an ID theft risk.


Ryan Naraine at eWeek writes
:

A dialog spoofing vulnerability in the popular Google Toolbar could be exploited by malicious hackers to execute malicious files or launch identity theft attacks, according to a warning from security researcher Aviv Raff.

Raff, a well-known hacker who regularly finds and reports software vulnerabilities, figured out a way to use a booby-trapped Web page to trick Google Toolbar users into adding malicious buttons to the toolbar.

Microsoft ships security assessment tool

Matt Hines at InfoWorld reports that Microsoft has delivered a new version of its Microsoft Security Assessment Tool.

Hines notes:

The latest iteration of MSAT promises expanded tests for assessing security threats, updated best practices, and an all new Infrastructure Optimization Security Assessment feature.

The free tool is now available for download.

Cenzic finds vulnerabilities in Gmail and IE

In a statement, Cenzic says:

Researchers at Cenzic discovered that a possible cross-site request forgery, in combination with the improper use of caching directives, could lead to cross-site scripting and leakage of sensitive information. A hacker could exploit this vulnerability to access a target’s confidential information. These vulnerabilities could also be exploited such that all users of a shared computer, who use Internet Explorer and share a user account — a common practice at computer kiosks in a library or Internet cafĂ© — could be vulnerable.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 3 Talkback(s)
XSS
XSS is perhaps the biggest threat (2nd to doing dumb things).
If you use Gmail be sure to not leave your login session open when otherwise surfing and make the password 'strong' and unique (as in not the same as for all of the site subscriptions you have).... (Read the rest)
Posted by: D. T. Schmitz Posted on: 12/19/07 You are currently: a Guest | | Terms of Use
Safe Surfing Best Practices  D. T. Schmitz | 12/19/07
Another way with Gmail  Narr vi | 12/19/07
XSS  D. T. Schmitz | 12/19/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline