Home

Forums

Web development

 

 

 

 
     
 
dna88 Web development and Technology Forum
 
Profile   Register   Memberlist   Usergroups   FAQ   Search  Log in
Google acts to cover up phishing hole

 
Post new topic   Reply to topic    dna88 Forum Index -> Web design and solution Discussion Forum
Author Message
hasnut
Expert User
Expert User


Joined: 28 Aug 2004
Posts: 201

Post Post subject: Google acts to cover up phishing hole Reply with quote

Google has fixed a security flaw in its web search service that could have allowed malicious hackers to modify its pages.

According to a report posted to the Bugtraq Security Focus list on Wednesday, Google's new Desktop Search tool did not prevent a hacker from inserting JavaScript, a programming language, into the web address of its page image or logo. That vulnerability could have allowed any rogue third party to change the appearance of Google's web page to ask for personal data such as credit card numbers from its visitors, what's known as a phishing scam, according to the warning.

Google said it has fixed the problem.

"Google was recently alerted to a potential security vulnerability affecting users of our website," a company representative said. "We have since fixed this vulnerability and all current and future Google.com users are protected."

The warning came only a week after Google released its newest web search product - a tool to search the files on a PC alongside web pages. Security experts have scrutinised the technology, with some interesting finds. Last week, security consultant Richard Smith found clues that could point to a coming instant chat client from the search giant.

Jim Ley, who runs a web log, posted the warning about Google's script-insertion flaw, which he said has affected Google's main site for as long as two years. But with the addition of Google Desktop, the flaw became more serious, he said, because "it places the results of a desktop search into the output of a regular Google search." He said that the flaw could have allowed third parties to make a record of all the searches people make.



Source: http://news.zdnet.co.uk/internet/security/0,39020375,39170858,00.htm
_________________
Sarder Hasnut
MCSD, CIW A

Need Low Cost Prefessional Hosting Contact me
Thu Oct 21, 04 6:00 pm
Back to top
hasnut View user's profile Send private message Visit poster's website MSN Messenger
emm
Power User
Power User


Joined: 13 Jul 2004
Posts: 310

Post Post subject: Reply with quote

I think, dude saw it coming(in the software review forum).
_________________
“You might say reality is the result of complex negotiations between the observer and the observed. But that is simply a point of view…”
Digital Bangladesh
Fri Oct 22, 04 4:40 am
Back to top
emm View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    dna88 Forum Index -> Web design and solution Discussion Forum All times are GMT - 7 Hours
Page 1 of 1

 

Partners and Resources

Bangladesh hosting company

Bangladesh web design

Driven by phpBB © phpBB Group