Google Desktop falls victim to XSS flaw - Silicon Valley Sleuth

Silicon Valley Sleuth, an insider's view from Silicon Valley
A blog from V3.co.uk





Other blogs
Download Junkie
Your daily dose of download discussion

IT Sneak
V3.co.uk's under cover reporter offers odds and ends from the odd end of the technology

Mac Inspector
Drills to the core of the latest Mac rumours and news

Security Watchdog
Sniffing out IT security issues

The Frontline
Insight into the latest tech news from V3.co.uk's team of reporters

V3.co.uk Labs
The latest UK business technology: quick reviews and first impressions




« Florence Night-Intel | Main | Britney Spears' hair goes online »

Google Desktop falls victim to XSS flaw

Online attackers can gain access to the Google Desktop application through a cross site scripting attack, researchers at Watchfire have discovered.

Sidebar We've seen cross site scripting vulnerabilities before, but this one is amazingly easy to demonstrate on your home or office computer, provided that you are running Google Desktop and haven't just updated it.

Curious? Go to your Google Desktop search page and type in the following:

under:<script>alert(This is all it takes)</script>

Once you enter that instruction, an alert box will pop up with the text "This is all it takes" inside. Displaying an alert box might not be anything serious, but that attacker can also insert more harmful commands that can expose confidential information, or worse.

Now go to Google and download the latest Google Desktop update.

Googleleak

Comments

Post a comment







Useful links: About | Privacy policy | Terms & conditions | Top of the page
© Incisive Media Investments Limited 2010, Published by Incisive Financial Publishing Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, are companies registered in England and Wales with company registration numbers 04252091 & 04252093