You are here: silicon.com > Software > Security Strategy

Security Strategy

Google search apps packing 'phishing flaw'

Hole could open websites to data theft...

Tags: flaw, phishing, google

By Joris Evers

Published: 28 November 2006 08:45 GMT

A security flaw in Google's search appliances could expose websites that use the products to info-stealing phishing attacks, experts have warned.

The Google Search Appliance and Google Mini are used by organisations including banks and universities to add search features to websites. A flaw in the way the systems handle certain characters makes it possible to craft a web link that looks as if it points to a trusted site but when clicked serves up content from a third, potentially malicious site.

John Herron, a security expert who maintains the NIST.org site, said in an email: "This vulnerability affects a lot of very large websites. It basically allows a virtual defacement of a website when following a malicious link."

Want more photos?

Click here to browse the full archive of our photo stories.

The vulnerability provides cyber crooks with a hook for phishing attacks. Phishing scams typically use spam email with a link to a fraudulent website.

Google found out about the problem last week, a spokesman for the company said in an email. "We have notified all customers and provided them with clear instructions on how to protect their appliances," he wrote, adding that no Google Search Appliance or Google Mini users have reported any exploits of the flaw.

Google sent an advisory to all customers on 22 November, the spokesman said. The vulnerability will also be addressed in the next release of the products, he added.

The cross-site scripting problem involves 7-bit Unicode Transformation Format (UTF) character encoding. Jeremiah Grossman, chief technology officer at WhiteHat Security, which specialises in web application flaws and protection, said: "This particular vulnerability is clever because of the encoding hack."

One way internet users can protect themselves against attacks that attempt to exploit the flaw in the Google appliances is to inspect web links. The rigged links will be very long, according to security experts.

Users of the Google appliances who have not heard from Google should contact the company for a fix. Grossman said: "Website owners must be diligent about finding and fixing vulnerabilities, [since] even products supplied by well-known brands possess these extremely common issues."

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Flash Developer / Designer

Experience of Flash video encoding and Flash-based video players You'll be working with our Creative Solutions team to develop original and engaging ...

PPC Analyst (SEM/SEO/PPC)

Key Responsibilities; - Running the day to day paid search activity across leading brands - Bid setting, campaign building, reporting and creative ...

Search Engine Optimization Specialist

Can demonstrate successful link-building campaigns that result in the acquisition of large volumes of inbound, high quality links. Must be fluent in ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: