iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Google Makes Its Sanity Check
Search:
[ insider_reports_insider ]

Google Makes Its Sanity Check



David Utter
Staff Writer
2006-07-06

SecurityProNews: Insider Reports Insider Reports RSS Feed


The search engine's personalized homepage service had been vulnerable to cross-site scripting attacks due to a failure to sanitize query strings.

Google Makes Its Sanity Check
Google Makes Its Sanity Check

A nasty vulnerability to cross-site scripting attacks reported on July 4th on the ha.ckers.org website has been repaired. The proof of concept attack that yielded the JavaScript output window demonstrating the exploit no longer works on Google.

Since Google is a trusted name and well-known global brand, an exploit of its services could have far-ranging impact. The Ha.ckers.org post tells more about just how bad cross-site scripting can be for the search advertising company:

Well, for starters, I can put a phishing site on Google. "Sign up for Google World Beta." I can steal cookies to log in as the user in question, I can use the credentials of the user to screen scrape any of the content off of the www cname, including changing options like adding my RSS feed to your page, or deleting them, etc… I can steal your phone number from the /sendtophone application via an XML RPC (AJAX) call via a POST method, get your address because maps.google.com is mirrored on http://www.google.com/maphp?hl=en&tab=wl&q= etc…

The article also suggested that the vulnerability could draw the attention of nefarious black hat types who want to boost their page rank by injecting their links and getting search engines to crawl them.

Since Google does not exclude the Personalized Homepage directory from being spidered by Googlebot, a scam site could temporarily end up with a page rank of 10, at least until Matt Cutts finds out about it and boots the site from the index.

---
Tag:

Add to Del.icio.us | Digg | Yahoo! My Web | Furl

Get all the updates in RSS:





About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds