ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Google Desktop flaws get patches

Candace Lombardi CNET News.com

Published: 22 Feb 2007 09:44 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Several flaws in the popular Google Desktop software could open PCs up to intruders and possible data theft, a security company has warned.

The search giant has released patches for the issues, which were reported by Watchfire in a paper published on Wednesday. One of the problems is a cross-site scripting flaw that could let an outsider look through files on a compromised machine.

Google Desktop applies the same technology found in Google's search engine to let users try to find items on their PC and on shared networked computers. The tool indexes and combs through emails, documents and files on the user's PC and stores web pages as part of its approach.

Hackers could use cross-site scripting to manipulate Google Desktop's functionality for their own ends, said Danny Allan, director of security research at Watchfire. The desktop application's integration with Google Search, Google's public internet search application, is a weak spot, he added. It means that the vulnerabilities found by Watchfire could have been exploited without the attack being detected by information protection systems, antivirus software and firewalls, he said.

Such an attack is different from traditional ones, because it relies on JavaScript code, rather than the insertion of binary code, to control Google Desktop. It uses the application remotely to search for confidential information, according to Watchfire's report.

That means that passwords and banking information stored either in computer files or in web page history could be accessed remotely by the attacker, Allan said.

Watchfire notified Google on 4 January of three vulnerabilities and one architectural flaw in the application, Allan said. Google responded to the security company on 1 February and asked for a few weeks before Watchfire went public with the information. The search giant has issued a patch for the problems.

"A fix was developed quickly, and users are being automatically updated with the patch," Google said in a statement. "In addition, we have another layer of security checks to the latest version of Google Desktop to protect users from similar vulnerabilities in the future."

The search company recommends that people make sure they are running the most recent version of Google Desktop.

It does not appear that anyone took advantage of the vulnerabilities and made attacks on Google Desktop users, both Watchfire and Google said.

However, Google Desktop is still vulnerable to these cross-site scripting attacks, Allan said, because of the "poor architectural decision" to include a link from Google web servers to the Google Desktop user's PC.

"The three vulnerabilities were fixed. We also recommended to Google that if there was not a link between Google.com and my machine, then [the hacker] would not be able to connect to my computer. We believe they should remove that link or give consumers a choice as to whether someone can connect from the public internet to their computer," Allan said.

The link enables a feature that places "Desktop" as one of the choices above the Google home page search bar, alongside choices such as "Images" and "News", once a user has downloaded Google Desktop. It allows Google Desktop users, no matter which browser they are in, to switch between searching the internet and searching their computer from the Google home page, according to the Watchfire report.

"If another vulnerability is found within Google Desktop, then the same devastating things could happen," Allan said.

Allan likened the architectural link to the internet to a swinging screen door. It's fine for it to swing out so that I can get out there, but it should not be allowed to swing back in, he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
3 out of 3 people found this useful


Full Talkback thread

1 comment

  1. Privacy security JimmyJackFunk21

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Messaging Support Analyst (AD,TREND protection,Exchange) BANKING

Other main functions of the role are troubleshooting & resolving cross platform message flow related issues, problem resolution & estate & patch ...

Messaging Support Analyst (AD,TREND protection,Exchange) BANKING

Other main functions of the role are troubleshooting & resolving cross platform message flow related issues, problem resolution & estate & patch ...

Strong JavaScript Developer / HTML / CSS / Ajax / Cross Browser - ASAP

You will have good experience of Java and Scripting Libraries as well as good working knowledge of Cross Browser Application. I am looking for a ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment