NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Webmaster / Google News

Google News


Google Security Flaw Brings Money to Malicious Websites

A new hole discovered in Google's RSS readers

By Bogdan Popa, Security and Search Engines Editor

19th of July 2007, 10:28 GMT

Adjust text size:


Which one? The security flaw:
Enlarge picture
Google is again involved in security advisory as the way it handles the RSS auto-subscribe functions might bring some unauthorized traffic to malicious websites. The security flaw
was discovered by Patrick Altoft from BlogStorm who wrote that almost any page is able to exploit the vulnerability in a matter of seconds. Let me explain you how it works: you surely saw at least one button placed on the websites that require you to click on it in order to receive feeds straight in your Google account. Usually, when you click on the button, Google asks you if you want to read the feeds in Google Reader or in iGoogle with a special gadget.

Well, a successful exploitation of the vulnerability makes the function not to ask you this and automatically subscribe to both Google Reader and iGoogle. This way, any website can record an increase of the readers' number that usually means more traffic and obviously more money. According to the report, the vulnerability can be easily exploited by placing a special code into their content.

"The problem is that unscrupulous websites can copy the links to Add to Google homepage or Add to Google Reader and open them up in an IFRAME for every visitor, meaning that anybody who visits their website while signed in to a Google account will suddenly have subscribed to the RSS feed on both Google Reader and the Google homepage automaticall," Patrick Altoft wrote.

Some users sustain the vulnerability was already fixed by the folks from Google Reader but Patrick Altoft sustains it is still available and exploitable by any bad-intended website. "Well, I was going to mention it to the Reader team, but it sounds like they've already responded. Cool," Matt Cutts, a Google engineer, wrote as a reply to the BlogStorm post.

TAGS:

google | security | rss | flaw | vulnerability
Read by 689 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.1/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


YouTube Security Flaws? Not Anymore...

New Censored Images for Google Earth

Second Critical Vulnerability in Google Desktop!

Google Makes Major Step for New Instant Messenger

Google Search: Safe or Not?

Google Used in Web Attacks

Security Verification for Google Search

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM