Translate To:


[code via DI]

Flash Updates

Subscribe By MailE-Mail Address:

Making Of

MP3

Tips Tricks Hacks

Google Tips

Firefox & IE Tweaks

Vulnerabilities Found

A Note About

Reviewed

Google Desktop Vulnerable To Attack

This Article Is Sponored By You! | Tuesday, June 5, 2007 by Salman Siddiqui | Comments
I am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita


Security researcher Robert Hansen, aka RSnake, has published details of a new attack on Google Desktop. Basically, Hansen found a man-in-the-middle attack, this time placing an attacker between Google and someone launching a desktop search query. From this position, the attacker is able to manipulate the search results and possibly take control of other programs on the desktop.

The attack scenario plays out like this: a user of Google Desktop makes a search query that is intercepted by an attacker. The attacker then injects Javascript that creates an invisible IFrame on the target URL page as well as makes the IFrame follow the user's mouse; the user is unaware. The attacker then injects more code to position a second query inside the user mouse IFrame. As the second query executes, the attacker then forces a meta-refresh to reload the page, and that forces Google Desktop to load as well as any program indexed by Google Desktop the attacker may desire. When user clicks the evil Google Desktop query, the malicious program executes.

Hansen writes: "This should drive home the point that deep integration between the desktop and the Web is not a good idea" since Google's site is unencrypted and therefore can be subverted by an attacker. But Hansen notes there are two caveats here: one, you need to have Google Desktop installed, and two, the attacker must be sophisticated enough to launch a man-in-the-middle attack upon you.

To illustrate the attack, Hansen provided an online video demonstration.

Related:
Search Google Without Ads
Hidden Google Pages
IE7 & FireFox SCARY Vulnerability
FREE Torrent Files Via Google

Technorati Tags: google hack

Labels: ,


My Mom Hates Me Blogging!Will You Help Me Show Her That I Am Good At It...Please?


==========Your Comments==========

>>>>>>>Click Here To Leave Your Precious Comments.<<<<<<<



“This Article”

Recently Published Articles

Grafpup 2.0, A Distro For Digital Artists, Availab... - Posted on Monday, June 4, 2007

Disable Vista's UAC But Be Cautious - Posted on Monday, June 4, 2007

Be A Orkut Watch Dog. Read Everyone's Scrap Withou... - Posted on Sunday, June 3, 2007

Taiwan's miCard Chosen As Global Memory Card Standard - Posted on Sunday, June 3, 2007

The Art of ‘Ware - a great read, now in PDF - Posted on Saturday, June 2, 2007

The Ultimate Reset Button - Posted on Saturday, June 2, 2007

Huge wind machine to simulate category three hurri... - Posted on Saturday, June 2, 2007

Mac OS X and Linux Bite the Dust – Windows Vista D... - Posted on Friday, June 1, 2007

AMD Selling Intel CPU As If It Hates Its Own Impre... - Posted on Friday, June 1, 2007

'Print Button' Specifically For Blogs by HP - Posted on Friday, June 1, 2007

Moved

I am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita

Money Makers


PPP Direct

Archives

Blogroll

Recent Comments