| 网站首页 | 文章中心 | 源码中心 | 集团邮箱 | 网站建设 | 暴风影音 | 酷狗2007 | 网际快车 | 留言板 | 软件下载 | 
您现在的位置: 人文软件园 >> 文章中心 >> Picasa看图软件 >> 文章正文  
Picture theft through hole in Google’s Picasa           ★★★ 【字体:
Picture theft through hole in Google’s Picasa
作者:Google    文章来源:google    点击数:    更新时间:2007-9-29    


The finders of the URI holes in Firefox and Windows are now targeting Google. In their blog, Billy Rios and Nate McFeters have described how attackers may steal all pictures organised using Google’s picture gallery software Picasa from users’ hard disks: It seems that they were able to load pictures from a PC onto a manipulated web server by combining various attack methods, such as cross-application scripting, cross-site scripting, URI tricks and a flash with ActionScript. 

As in the case of similar problems affecting other applications, the main source of this vulnerability is that Picasa registers the URI picasa:// during installation and can thus be accessed and partly controlled by web pages. Rios and McFeters have used this weakness to make their client believe that an important Picasa update has been made available on a manipulated web page, with the supposed update being triggered through a fake button. Instead of being directed to the Google pages, the user lands on a malicious server that copies the pictures from the hard disk. Since this process requires some time, a fake progress bar is displayed to simulate the download from Google’s Picasa web site.

According to Rios and McFeters, this kind of attack is rather complex and consists of several steps, requiring several scripts. They have however published most of these scripts, written by Rob Carter. The report on this vulnerability includes a series of pictures to illustrate the attack. There is no short-term solution to this problem, and deregistration of the URI is no real help either, since, according to Rios, key Picasa processes would in that case cease to function.

But these are not the only problems facing Google. For instance, Google Urchin, the install version of Google Analytics, contains a cross-site scripting vulnerability that can easily be exploited by web pages to steal the Google log-in data. A video demonstrates how the exploit works. The report also states that Google was informed of this problem on June 25 and is currently working on a fix.

Other reports speak of an XSS vulnerability in Google’s Search Appliance, a scalable hardware and software package for enterprises, used to operate a search engine within corporate networks and on public web pages. This vulnerability could be exploited to manipulate the search results displayed to users.

Finally, XSS vulnerabilities on Google.com can be used to steal contact information and messages from Gmail accounts. These holes, which are based on insufficient sanitization of the STYLE tags, have now been fixed.

文章录入:renwen@renwen.net    责任编辑:renwen@renwen.net 
  • 上一篇文章:

  • 下一篇文章: 没有了
  • 发表评论】【加入收藏】【告诉好友】【打印此文】【关闭窗口
    最新热点 最新推荐 相关文章
    固顶文章picasa看图软件中文官方免费下载
    推荐文章教你玩转Picasa图片上传
    普通文章Picasa 网络相册
    推荐文章Google Picasa网络相册扩容至1GB
    推荐文章Google Picasa网上相册结束测试已…
    推荐文章Google Picasa v2.5 (皮擦萨)测…
    普通文章如何创建自定义幻灯片演示?
    推荐文章Google照片管理软件-用户指南
    普通文章Picasa 支持 RAW 格式的图片吗?
    推荐文章Neven Vision加入Google 图片软件…
    推荐文章教你玩转Picasa图片上传
    推荐文章Google Picasa网络相册扩容至1GB
    推荐文章Google Picasa网上相册结束测试已…
    推荐文章Google Picasa v2.5 (皮擦萨)测…
    推荐文章Google照片管理软件-用户指南
    推荐文章我如何将图片从电子邮件导入 Pic…
    固顶文章picasa看图软件中文官方免费下载
    推荐文章Neven Vision加入Google 图片软件…
    教你玩转Picasa图片上传
    百度成为最大广告平台 高续费…
    google要人还域名的邮件
    Picasa 网络相册
    Google Picasa网络相册扩容至…
    泰国总理他信宣布全国进入全…
    六款网络相册客户端软件横评
    Google Picasa 小秘密
    It's free and installs…
    How do I block "Messenger …
      网友评论:(只显示最新10条。评论内容只代表网友观点,与本站立场无关!)