Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

November 8th, 2012, 15:40 GMT · By

BLOG

Experts Find DOM-Based XSS Vulnerability in Google.com

SHARE:

Adjust text size:


Experts used DOMinatorPro to find DOM-based XSS in Google.com Enlarge picture - Experts used DOMinatorPro to find DOM-based XSS in Google.com
Security researchers from Minded Security have identified a document object model (DOM)-based cross-site scripting (XSS) vulnerability on Google.com.

The security hole has been identified with the aid of DOMinatorPro - a runtime JavaScript DOM XSS analyzer.

According to the researchers, DOMinatorPro revealed a piece of code in googleadservices.com /pagead/landing.js which used invalidated input to build the argument for two “document.write ” calls.

They found that the buggy JavaScript had been utilized by google.com/toolbar/ie/index.html (both HTTP and HTTPS).

“[This] means that one more time a (almost) 3rd party script introduces a flaw in the context of an unaware domain,” Minded Security’s Stefano Di Paola explained.

Di Paola suggested one workaround, but Google decided to address this issue by removing the problematic script altogether.

Unlike the traditional XSS vulnerabilities that occur in the server-side code, DOM-based XSS affects the script code in the client’s browser.

TELL US WHAT YOU THINK:

1,608 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Experts Test Security Headers of Top 1 Million Alexa Websites

Sophos Addresses Remote Code Execution, Other Vulnerabilities in Antivirus Product

Telecom Italia Hacked by Anonymous, 30,000 Credential Sets Stolen

Experts Find DOM XSS Flaw in “+1” Button of Google Plus - Video

Persistent XSS and SQL Injection Flaws on ESET Taiwan Website Fixed

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM