Tutorial

Go Back   Tutorial > Technology > Home security tips

Forum overview

Latest topics
Show:

Portalsearch

Advanced Search

Statistic
Topics: 34936
We welcome our newest user: VomaHeeseex
New users:
11-22-2008
- VomaHeeseex
11-22-2008
- ToomiFearma
11-22-2008
- Greevedic
11-22-2008
- OnesStelsnemi
11-21-2008
- Hauhpaimupt


Google Open to Frame Injection Attack


Home security tips

Sponsored Links:

Reply
 
Thread Tools Search this Thread Display Modes

  #1  
Old 10-11-2008, 07:20 PM
LapTop's Avatar
LapTop LapTop is offline
Administrator
 
Join Date: Apr 2007
Posts: 21,889
Google Open to Frame Injection Attack

Sponsored Links:
Wayne Porter's Google Open to Frame Injection Attack leads to an interesting report by Aviv Raff of his discovery over six months ago -- a discovery reported to Google, yet still without response other than they're looking into it:
"You all learned about the value of sharing. When I was a kid my mother taught me that I should share my stuff with my friends. Unfortunately, sharing is not always a good thing. Especially, when talking about sharing web-applications across domains.
Over six months ago I've discovered an interesting, yet troubling, issue - Google.com suffers from a cross-domain web-application sharing security design flaw. There are several Google web applications which are accessible over multiple google.com subdomains. The following are some of those web-applications and subdomains:
  • Google Maps (maps.google.com)
  • Google Mail (mail.google.com)
  • Google Images (images.google.com)
  • Google News (news.google.com)
  • Google.com (Google Search, Google Accounts, Google Apps, Google History, etc.)"
Following the Proof of Concept by Adrian Pastor and no further response from the Google security team, the decision was made to publish the findings.

References:

Frame Injection Fun
Frame Injection Vulnerabilities
Google Open to Frame Injection Attack
Sharing is not always a good thing









Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Computer security news & information, help, tips and more, licensed under a
Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Unported License.
Sponsored Links:
Reply With Quote
Reply

Sponsored Links:

Compare price

Compare products

Download software


Free Download Softwware




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Google Invites Asus To Join Open Handset Alliance LapTop Mobile Phone 0 09-20-2008 09:16 AM
Google Introduces Photostream Open Source Sample Application LapTop Mobile Phone 0 09-11-2008 03:01 PM
Open Websites in Google Chrome from Firefox LapTop Xp tips 0 09-05-2008 07:27 PM
Edit Animated GIF Images Frame by Frame with GIF Maker LapTop Xp tips 0 07-09-2008 04:30 PM
Open Your Google Docs Presentations in Microsoft PowerPoint LapTop Xp tips 0 04-09-2008 04:41 AM



All times are GMT. The time now is 10:59 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.

RSS 2.0 HOME