Google Downplays Talk of Security Vulnerabilities

執筆者
Brian Prince
Brian Prince
Published: Oct 13, 2008
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Google is downplaying concerns about security issues tied to cross-domain Web application sharing that could leave Google users open to attack.

Security researcher Aviv Raff posted general details of a cross-domain Web application sharing flaw to his blog Oct. 10. According to Raff, the vulnerability affects several Google applications available across Google subdomains, including those used by Gmail, Google Maps, Google Images, Google News and Google search. When used in conjunction with other vulnerabilities, the issue could pose problems, he wrote.

Click here to read about how some hackers are using Google Trends to determine what to put on malicious sites.

“For instance, one small XSS issue in Google Maps can now be exploited to hijack Google, Gmail or Google Apps accounts by bypassing the browser’s Same Origin Policy,” Raff wrote. “There were several XSS issues reported in the past, on some of the google.com subdomains, which are now fixed.”

A second researcher, Adrian Pastor, posted proof-of-concept code on GNUCitizen.org showing that attackers can inject their own pages while the browser still shows the Google domain in the address bar. In Pastor’s example, he created a fake log-in page an attacker could use to trick someone into entering log-in information. Pastor wrote on GNUCitizen:

“I thought that showing a live example would help our readers get an idea of what frame injection looks in action. For that purpose, I prepared a rather not elegant proof of concept which takes advantage of the Google Images service. What’s neat is that although the legitimate URL would normally use the images.google.com domain, Google also allow us to use other google.com subdomains such as mail.google.com which is used by Gmail. This is ideal, as we’re trying to accomplish a frame injection attack which can be used to perform phishing attacks against Gmail users.“

Raff claimed he notified Google of the problem in April and company officials said they were looking into it. As of Oct. 10, he hadn’t received any word of a fix, hence his post. When contacted the same day, a Google spokesperson said the company is aware of the issue and has taken steps to prevent it in cases where there are security consequences.

Advertisement

While Pastor’s example page may seem legitimate at first glance, there are ways for users to determine its authenticity. For one thing, the page’s address bar clearly marks it as an HTTP page, whereas all Google’s log-in pages are HTTPS. In addition, Google’s Safe Browsing API also works to protect users from phishing pages.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。