[ insider_reports_insider ] Google Makes Its Sanity Check
David Utter Staff Writer
2006-07-06
Insider Reports RSS Feed
The search engine's personalized homepage service had been vulnerable to cross-site scripting attacks due to a failure to sanitize query strings.
 | | Google Makes Its Sanity Check |  |
A nasty vulnerability to cross-site scripting attacks reported on July 4th on the ha.ckers.org website has been repaired. The proof of concept attack that yielded the JavaScript output window demonstrating the exploit no longer works on Google.
Since Google is a trusted name and well-known global brand, an exploit of its services could have far-ranging impact. The Ha.ckers.org post tells more about just how bad cross-site scripting can be for the search advertising company:
Well, for starters, I can put a phishing site on Google. "Sign up for Google World Beta." I can steal cookies to log in as the user in question, I can use the credentials of the user to screen scrape any of the content off of the www cname, including changing options like adding my RSS feed to your page, or deleting them, etc… I can steal your phone number from the /sendtophone application via an XML RPC (AJAX) call via a POST method, get your address because maps.google.com is mirrored on http://www.google.com/maphp?hl=en&tab=wl&q= etc…
The article also suggested that the vulnerability could draw the attention of nefarious black hat types who want to boost their page rank by injecting their links and getting search engines to crawl them.
Since Google does not exclude the Personalized Homepage directory from being spidered by Googlebot, a scam site could temporarily end up with a page rank of 10, at least until Matt Cutts finds out about it and boots the site from the index.
---
Tag: Google
Add to Del.icio.us | Digg | Yahoo! My Web | Furl
Get all the updates in RSS:
About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.
More insider_reports_insider Articles
Insider Reports RSS Feed
|
|