ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Google fixes security hole

Joris Evers CNET News.com

Published: 22 Dec 2005 09:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Google has fixed a security flaw that had opened the door to phishing scams, account hijacks and other attacks, security researchers said on Wednesday.

The flaw, known as a cross-site scripting vulnerability, existed because Google did not properly secure its mechanism for two error pages, according to Web security company Watchfire, which discovered the problem. Watchfire posted to a security mailing list an advisory on the issue.

Attackers could exploit the flaw to launch phishing scams or steal a user's credentials, said Ory Segal, director of security research at Watchfire. Phishing scams are designed to trick people into giving up sensitive information such as usernames, passwords, credit card details and Social Security numbers.

"When we looked at the Google site, we saw that they are very good with their Web application security, but it looked like they forgot about this obscure variant of cross-site scripting," Segal said.

Google confirmed that it was alerted "a little while ago" and fixed the flaw. "No user data was compromised and we applaud Watchfire for following industry best practices for vulnerability disclosure," a Google representative said in an emailed statement.

The problem existed in the mechanism Google uses to generate error pages for forbidden redirects and pages that don't exist on the Google Web site, according to Watchfire. An attacker could use 7-bit Unicode Transformation Format (UTF-7) characters to exploit the flaw, Watchfire said.

In an attack, the target would click on a malicious link or visit a specially crafted Web page, Segal said. "You would then see the Google error page in your browser and with that message also receive malicious JavaScript code planted in the link," he said. Because the code is coming from Google, it can access data such as Google cookies, he said.

Google was alerted on 15 November and fixed the problem on 1 December by using character encoding enforcement, according to Watchfire. The security company in its advisory commends Google for its cooperation and communication regarding this vulnerability.

Cross-site scripting flaws are found regularly. Earlier this year, Finjan Software spotted a similar bug in Google's Web site as well as Microsoft's Xbox 360 Web site. Such flaws have also been identified in Yahoo's Web-based email service.

Earlier this year, a security flaw in Google's email service, Gmail, was identified and fixed. The flaw could have allowed attackers to hijack Gmail users' in-boxes.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
90 out of 182 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

UNIX/NETWORK SYSTEMS ADMINISTRATOR

Requirements - Proven linux sys admin experience (preferably RedHat) - Shell Scripting (bash, perl, php, xml) - Apache Webserver Admin - Database ...

Unix / Linux Redhat Systems Administrator Scripting, West of London

Unix / Linux Redhat Systems Administrator Scripting, Oracle, MySql, DNS, DHCP, Apache My client is a FSTE 100 blue chip organisation looking for ...

Front End Developer XHTML, CSS, Javascript, W3C

The successful candidate will need to: -Use information/interaction design skills to develop and document site structures, navigation flows, wire ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment