Silicon Valley Sleuth, an insider's view from Silicon Valley
A blog from vnunet.com



Other blogs
PCW Inter@ctive
Your views, your comments, your say

Security Watchdog
Sniffing out IT security
issues

The test bed
The hottest products, news and gossip from PCW's
Labs.

IT Sneak
IT Sneak Blog rummages in the dustbin of IT events.

Backbytes
An irreverent and offbeat look at the lighter side of technology

InterActive Home
Your complete guide to home entertainment technology

Taking Stock
Gags and Gossip from Accountancy Age.

Gizmodo
The gadgets weblog.



« Florence Night-Intel | Main | Britney Spears' hair goes online »

Google Desktop falls victim to XSS flaw

Online attackers can gain access to the Google Desktop application through a cross site scripting attack, researchers at Watchfire have discovered.

Sidebar We've seen cross site scripting vulnerabilities before, but this one is amazingly easy to demonstrate on your home or office computer, provided that you are running Google Desktop and haven't just updated it.

Curious? Go to your Google Desktop search page and type in the following:

under:<script>alert(This is all it takes)</script>

Once you enter that instruction, an alert box will pop up with the text "This is all it takes" inside. Displaying an alert box might not be anything serious, but that attacker can also insert more harmful commands that can expose confidential information, or worse.

Now go to Google and download the latest Google Desktop update.

Googleleak

February 22, 2007 at 01:23 AM | Permalink

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/24766/16301918

Listed below are links to weblogs that reference Google Desktop falls victim to XSS flaw:

Comments

Post a comment






 

Useful links: About | Privacy policy | Terms & conditions | Top of the page
© Incisive Media Ltd. 2008
Incisive Media Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, is a company registered in the United Kingdom with company registration number 04038503