HZRN.COM
welcome to my space
X
Search:  
Welcome to:hzrn.com
NAVIGATION - HOME

Don't Get Googled by Hackers!

Published by: cfz 2008-11-21

An exploit in the world's most popular search engine's toolbar could leave users vulnerable to malicious users.

Including and prior to Google's version 1.1.58 of its toolbar, users are at risk from hackers who can execute the following tasks: control all visual configuration options; hijack the toolbar and reroute searches; execute arbitrary commands; read local files; tap to key presses in the toolbar's search box; enable features with privacy implications; clear the toolbar's history; uninstall the toolbar.

Google boasts that its toolbar "increases your ability to find information from anywhere on the web and takes only seconds to install."

The company who discovered the flaws, Israel's GreyMagic Software, detailed the vulnerabilities a malicious user may exploit as such:

    Dont let your navigation system fool you | Tech News on ZDNet::
    Two Italian hackers have figured out how to send fake traffic information to Barisani and hardware hacker Daniele Bianco discovered that the system used by
    http://news.zdnet.com/2100-1009_22-151908.html
    HOME
    Hacker News | Ask YCNews: Any lady hackers using the site?::
    how smart you are, if you dont spend time on something, you wont accidentally get good at it. follow the technical discussions, with lots of Googling.
    http://news.ycombinator.com/item?id=101506
    HOME
  • Control all visual configuration options -- The method of registering changes in options to the Google toolbar is very insecure. The toolbar is using a special URL to inflict the changes. However, it doesn't let the changes occur if the current document is outside of google.com or the special res:// protocol
  • EVIL EDITOR: Update::
    Why you dont get published. About Me. Name: Evil Editor. Location: United States for a government agency that every hacker wanted to get inside and EF
    http://evileditor.blogspot.com/2008/02/update.html
    HOME
    When typing to the Google toolbar, the currently loaded document still receives all the keyboard events. This flaw is trivial to exploit, by setting a simple "onkeydown" event handler in the document level and waiting for input
  • Enable features with privacy implications -- the toolbar comes with two features that have privacy implications; these are the "PageRank" feature and the "Category" feature
  • Clear the toolbar's history -- the toolbar has an option to save searches made by it
  • Hijack the toolbar and reroute searches -- to search, the toolbar uses a special option called "GoogleHome". An attacker can change the value of the "GoogleHome" option and then change the URL. Once executed, Web searches would be routed through the attacker's web site. The attacker would be able to log the searches and identify users. The attacker will then be able to brand the user and offer him services according to the searches made. After logging the search information, the attacker can simply forward the request to Google to remove any suspicions the user may have
  • The future of malware: Trojan horses | TalkBack on ZDNet::
    I dont know of any Office vulnerability that involves privilege escalation so that means the troja Googling Google. Digital Cameras. Hardware 2.0. Laptops
    http://talkback.zdnet.com/5208-1009-0.html?forumID=1&threadID=26226&messageID=492505&start=0
    HOME
    Execute arbitrary commands -- The toolbar command mechanism exposes a very dangerous feature; the script passed to the command will run in the same context as the current document. The toolbar command mechanism accepts two kinds of URLs, any URL in the google.com domain and any res:// URL

Google has responded to the suggestions of GreyMagic, and quickly furnished a fixed version, which began distributing on Wednesday using the auto-update feature in the Google toolbar.

To see exploit demonstrations, please visit here.


Serious Vulnerability Uncovered in Apache 2.0
OASIS, W3C to Helm Web Services Security Forum

  • now veterinarians seek their dues india
  • india committed to share experience in controlling avian flu
  • risk communication on borrowed time
  • bird sale ban in 7 districts
  • hygienic lab scientist to do bird flu training in india blog for gazetteonline
  • egypt india egyptian min of health to visit india discuss fight against bf
  • a bird flu india editorial
  • bengal s poultry situation
  • will indian poultry get a waiver too
  • karunanidhi visits flood hit areas
  • india alert after pak bird flu reports
  • india unveils roadmap to combat avian influenza
  • vigil against bird flu stepped up in goalpara
  • avian guests get health check ups
  • india beating back bird flu
  • microbiologist will train technicians in india to test for bird flu
  • indian poultry rearing practices not suitable fiapo
  • bird flu impact pm expresses concern to buddha
  • india icar develops vaccine to combat h5n1
  • manipur vet department falls back on entertainment to raise awareness
  • no food grain use for bio fuel production pm
  • assam india over 10 000 jobs in health dept
  • kerala plans to wipe out mosquitoes before monsoon
  • the need of the hour is breathing masks
  • warden message kolkata india
  • centre reviews bird flu situation
  • kashmir gets equipped in monitoring birds to maintain a census
  • #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info about Don't Get Googled by Hackers! , Please add it free.

    About us -Site map -Advertisement -Jion us -Contact usExchange linksSponsor us
    Copyright© 2008 hzrn.com All Rights Reserved
    Site made&Support support@hzrn.com    E-mail: web@hzrn.com