main

Google Gadgets can be misused by phishers

Slimy   on 19 August 2007 - 18:37 · 1 comment & 1414 views

Advertisement (Why?)
Google Gadgets are little programs that gather information on the Web and then display them on multiple Web pages, making it easy for Webmasters to display everything from sports scores to astronomical data across their sites. The domain used to host small Google Gadget applications written by Web developers could be misused by phishers to get around antiphishing filters. Attackers could create a phishing site on the gmodules.com domain and then send that URL to victims. Because Google's gmodules.com domain is trusted by antiphishing filters, victims are not warned by their browser's filtering software.

Security researcher Robert Hansen, CEO of SecTheory and a frequent critic of Google, reported the issue to the company's security team, but he was not satisfied with their response. He says Google told him that what he sees as a flaw is simply part of the site's expected behavior. Hansen insists Google should restrict the URLs that can use this domain to avoid helping online criminals.

News source: InfoWorld

Post a comment · Send to friend Comments · There are 1 additional comments
#1 dandin1 on 20 Aug 2007 - 00:36
*shurg* Not much of an exploit. Phishing filters shouldn't even be necessary, just don't enter your banking account password at a random site!

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)