Welcome to WebmasterWorld Guest from 54.163.49.19

Forum Moderators: goodroi

Message Too Old, No Replies

Google Search Appliance/Mini Flaw Adds Phishing Hole

     
5:19 pm on Nov 28, 2006 (gmt 0)

Administrator from GB 

WebmasterWorld Administrator engine is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month Best Post Of The Month

joined:May 9, 2000
posts:22318
votes: 240


A security flaw in Google's search appliances could expose Web sites that use the products to information-stealing phishing attacks, experts warned Monday.

The Google Search Appliance and Google Mini are used by organizations including banks and universities to add search features to Web sites. A flaw in the way the systems handle certain characters makes it possible to craft a Web link that looks like it points to a trusted site, but when clicked serves up content from a third, potentially malicious site.

"This vulnerability affects a lot of very large Web sites," John Herron, a security expert who maintains the NIST.org site, said in an e-mail. "It basically allows a virtual defacement of a Web site when following a malicious link."

Google Search Appliance/Mini Flaw Adds Phishing Hole To WebSites [news.com.com]

6:26 pm on Nov 28, 2006 (gmt 0)

Senior Member

WebmasterWorld Senior Member 10+ Year Member

joined:Feb 13, 2005
posts:1077
votes: 0


Google sent out an email on Sunday detailing the vulnerability and giving a workaround, noting that a resolution is in development.

Chip-