Web Hosting Sitemap  
Find Affordable Web Hosting Providers - Tophosts.com
  

Find Affordable Web Hosting


Go Back   Web Hosting Forum - Webhosting Discussions at TopHosts.Com > Web Hosting News
User Name
Password


Reply
 
Thread Tools Display Modes
Old 06-02-2007, 03:15 AM   #1
TopHosts NewsMan
NewsMan
 
Join Date: Apr 2006
Posts: 16,761
TopHosts NewsMan is on a distinguished road
Post Zero Day Hole in Google Desktop

40by40 writes "A Web application security specialist has figured out a way to launch man-in-the-middle attacks against a computer with a fully patched Google Desktop installed. With knowledge of the Google Desktop security model (a combination of one-time tokens, iFrames and JavaScript), hacker Robert Hansen figured out a way to sit between a target launching a Google search query and manipulate the search results to take control of other programs on the desktop. From the article: 'This should drive home the point that deep integration between the desktop and the web is not a good idea, without tremendous thought put into the security model. As Google's site is unencrypted, and they place their content that can run executables on their site, it can be subverted by an attacker," Hansen warns. Hansen's advisory come just days after a Chris Soghoian's exposé of a similar man-in-the-middle attack scenario against a remote vulnerability in the upgrade mechanism used by a number of commercial Firefox extensions.'"Read more of this story at Slashdot.




Link To Original Article
TopHosts NewsMan is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


» Links
   webmaster forums
   merchant select

» Links


All times are GMT -4. The time now is 12:00 PM.




SEO by vBSEO 2.4.0