Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

November 28th, 2006, 09:30 GMT · By Bogdan Popa

GOOGLE VULNERABLE TO ATTACKS!

SHARE:

Adjust text size:


Google is one of the companies that never had a problem with vulnerabilities, bugs or security flaws. It seems like Google Search Appliance
is affected by a flaw that will add a phishing hole to sites visited.

NIST.org posted a message on their site to explain the vulnerability and how does it work: "What do several Banks, Credit Unions, Universities, countless business websites, dozens of government websites, and Google all have in common? A new Cross-Site Scripting (XSS) vulnerability. One that affects a lot of large websites, many that are ripe for phishing exploits," they started the announcement.

"This vulnerability is in the Google Search Appliance. A self-contained little pizza box of a computer that is built from the ground up to be a search engine for a company's website or file server. According to Google, prices for this device start at less than $2,000 and it can be up and running in less than an hour.

The problem involves using UTF-7 character encoding to bypass special character input handling. Normally these special characters (eg; ) are either filtered out or explicitly handled as plain text so they aren't echoed back in the search results as HTML or JavaScript," they added.

Google hasn't yet released any official statement but I hope the company will release a patch soon because it's obvious that security is the most important fact of the Internet.

TELL US WHAT YOU THINK:

1,340 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


STOP! This Website Can Harm Your Computer!

Microsoft Labels Gmail as Virus

Google Pays Close Attention to Users

Google Search and The Transcoder

Google Improves Google Apps for Your Domain

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM