Showing posts with label attacker. Show all posts
Showing posts with label attacker. Show all posts

Wednesday, April 16, 2008

Google Apps hit by session-stealing attack

A security research worker have uncovered a serious flaw in Google Spreadsheets, which could give an aggressor entree to all of a
user's Google services.

While the bug, an XSS (cross-site scripting) flaw, have now been fixed by Google, it is an indicant of the hazards that can
attach to the growth popularity of SaaS (Software as a Service), according to research worker Truncheon Rios, who uncovered the problem.

Because of the manner Google constructions its hallmark processes, a single XSS onslaught can present entree to all of a user's
Google services and documents, Rios said.

"With this single XSS, I can read your Gmail, backdoor your beginning codification (code.google.com), steal all your Google Docs, and
basically make whatever I desire on Google as if I were you," he said in a blog post.

The work relied on the manner Internet Explorer finds the content type of waiter responses, ignoring the content-type
heading in certain circumstances. Browsers like Firefox, Opera, and Campaign can be made to share the same behavior, Rios said.

"Developers demand to understand the niceties of how the popular web browsers manage assorted content-type headers, otherwise
they may set their web application at hazard of XSS," he wrote.

To transport out the attack, Rios injected hypertext markup language into the first cell of a table, along with Javascript designed to expose the
user's cookie. IE then rendered the content as HTML, allowing the cooky to be viewed.

The onslaught could be delivered via a nexus to the specially formed spreadsheet, Rios said.

"To be fair, Google included a elusive defence to protect against content-type sniffing (padding the response), but those protection
measurements failed (with a small goad by me)," he wrote.

Rios recently publicized a exposure (also now fixed) in Google Code allowing the larceny of passwords.

Google Apps began as a set of hosted services, but Google this calendar month have begun rolling out offline entree to them, beginning
with the word processor, Google Docs.

Over the adjacent three hebdomads or so, Google will turn on the characteristic for all word processor users, giving them the ability to
see and redact written documents offline. During the same clip period, Google Docs' spreadsheet will derive offline ability for viewing,
but not redaction documents.

Google Docs' 3rd component, an application to do microscope slide presentations, will stay for now without offline access. However,
Google have programs to widen the offline entree to it and to other hosted services in the Google Apps suite, of which Docs is
part. Apps also includes Gmail, Calendar, Talk, and others.

Thursday, December 13, 2007

Vulnerabilities Found In Microsoft Access And HP Laptop Software - InformationWeek




The United States Computer Emergency Readiness Team (US-CERT) this hebdomad issued two warnings about public work code.


On Monday, the authorities security grouping said that there's a in the manner that Microsoft Entree manages Microsoft Entree Database (.MDB) files. Opening maliciously-crafted .MDB data files may let an aggressor to carry distant codification without further user interaction, the grouping said.


US-CERT did not supply inside information beyond stating that the exposure was being actively exploited. A proof-of-concept have been available since November 16.


Microsoft sees .MDB data files to be unsafe, along with many other data file types. "Microsoft clients should be aware that gap insecure types of data data files could do malicious harm to computing machine systems," the company states in its . "These files could incorporate viruses or Dardan Equus caballus programmes and could be used to change or to cancel information that is stored on the computer. These data files could also be used to direct information that is stored on a computing machine to other computers. We urge that clients only unfastened these types of data data data data data data data data files after clients verify that the transmitter is trustworthy and that the transmitter intentionally sent the file."


Some of the files types Microsoft classes as insecure are: programme files (*.exe), batch files (*.cmd and *.bat), book files (*.vbs and *.js), Microsoft Entree files (*.mdb) and macro instructions in Microsoft Word files (*.doc) Oregon in Microsoft Excel files (*.xls). The Microsoft Entree stack buffer flood exposure was not among those Microsoft fixed on December 11 in its monthly security spot bulletin.


On Wednesday, US-CERT said it was also aware of studies of a possible in the horsepower Information Center Software establish on horsepower Laptops. The grouping said that the flaw could let an aggressor to carry distant codification on the affected laptop computer computer or change the laptop's system registry.


A for the horsepower software system flaw was posted on Tuesday.