Home » Google
Bookmark and Share

Google Cross Domain Bug Proof of Concept

Written by Sandeep (351) on 11 October 2008 and received No Comments

260 google chrome Google Cross Domain Bug Proof of ConceptGoogle’s Gmail service suffers from security flaws that make it trivial for attackers to create authentic-looking spoof pages that steal users’ login credentials, a security expert has demonstrated. Google Calendar and other sensitive Google services are susceptible to similar tampering.

A proof-of-concept (PoC) attack, published by Adrian Pastor of the GNUCitizen ethical hacking collective, exploits a weakness in the google.com domain that allows him to inject third-party content into Google pages. The result is this page, which allowed him (at time of writing, anyway) to display a fraudulent Gmail login page that displayed mail.google.com in the browser’s address bar.

Download Mozilla Firefox now!

Get Your Blog Migrated freely to WordPress!

Related posts:

  1. Bing.com accepting Google but doesn’t accepts Microsoft as it’s Sub-Domain. Im having the Proof
  2. How to Create a Page Template in WordPress
  3. The Google Image Search Engine Gets Makeover
  4. Google Search Advanced Operators – Cheat Sheet
  5. Dreamhost Hosting Discount: Webhosting + Free Domain for just $2.95

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

*All comments will be moderated, Read our Comments Policy.

CommentLuv Enabled