Gadget lovers were dealt a blow on Wednesday when two researchers outlined what they called a "hole" during a Black Hat presentation. "The attacker can forcibly install Google Gadgets; they can read the victim's search history once a malicious gadget has been installed in some specific circumstances; they can attack other Google Gadgets; they can phish usernames and passwords from victims, and so on," said Robert Hansen, also known as RSnake, a founder of security consultancy SecTheory. "Really, the sky is the limit, once the browser is under the control of an attacker. And that point is exacerbated by the fact that people trust Google be a trustworthy domain, making the attacks even easier." Hansen said that users who are most vulnerable to attack are those who use Google and specifically Gmail since the Web-based e-mail service requires them to be logged in. The attack relies on users intentionally adding modules themselves; a user may be tricked into adding malicious Google modules to his iGoogle homepages. "These users are almost all using javascript and normal Web browsers, making them easing pickings for many different classes of attack," he added.
















However, I find it unacceptable that one gadget would be allowed to add more, and snoop/interfere with others. In some cases, a user might want a new gadget to read his/her calendar. But there should be some privacy/isolation set as default, and the user must authorize a link.
This sounds like a free-for-all once installed.
seems maybe MS is behind this attack.....LOLOL!...I bet users of Hotmail and MSN Search are safe
It will be a Search-worthy domain
Last edited by guruparan on 08 Aug 2008 - 20:05
How do you determine anything is trustworthy?
How do you determine anything is trustworthy?
If it phones home or autoupdates it's not trustworthy.
You mean like Mozilla Firefox?
http://www.neowin.net/forum/index.php?showtopic=645847
Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!
Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.