Welcome Guest ( Log In | Register )

  Recent Software News
Phel Trojan targets Windows flaw
Cabir cell phone threat worsens
19 LingvoSoft dictionaries for Wind...
Microsoft posts critical configurat...
Apple ships Mac OS X update
  Recent Gaming News
Electronic Arts to buy into Ubi Sof...
Halo 2, San Andreas key drivers of ...
Sony Says All Systems Go for PSP La...
Nvidia to work on PlayStation 3 chi...
New Command & Conquer Game Unveiled
  Recent Reviews
 · CoolerMaster Aerogate 3 A...
 · CoolerMaster AquaGate Wat...
 · OCZ Copper BGA Ramsinks
 · Mapower Warps Portable 3....
 · Vantec - PCI & RAM Slot P...
  Recent Forum Posts
Windows XP Sp2 Problems
Leadtek A350XT TDH and overclo...
FX5900U vs 9800Pro
Google Gmail Invites
Doom 3 SDK Released
  Announcement

Welcome to AusPCWorld - Australia's Leading PC Technology News & Reviews site.



> AusPCWorld > Tech News > Google Fixes Desktop Search Flaw






   
Google Fixes Desktop Search Flaw
Posted by mitchy_g on 21 Dec 2004 - 11:21 0 comments
Previous Post | Tech News | Next Post
 
Google fixed a flaw in its beta desktop search tool that could have given hackers access to users' local searches, officials said Monday.

The vulnerability, discovered and reported by three members of Rice University's computer science department, proved it was possible for a malware (define) writer to grab information from a Web page containing any desktop searches performed by a user infected with a JavaScript- or applet-based program.

According to the paper "Attacks on Local Searching Tools" by Dan Wallach, Seth Nielson and Seth Fogarty, Google's desktop search program creates a local Web server but only allows the user to get at the data through localhost or 127.0.0.1 connections.

Given Google's Web-centric nature, a desktop search also simultaneously conducts a Web search on Google's site, returning the query and appending it to the desktop search.

The researchers were able to determine that the integration of the desktop and Web searches was conducted by some agent running locally, based on any HTTP (define) request made to the Google Web server. From there, it was a matter of finding a method to prompt a Web search, which would then automatically include the local search.

"While an attacker would not be able to read the victim's files directly, the search results often contain snippets of the file results that will be visible to the attacker."

News source: InternetNews



There are 0 additional comments, Post a comment | View printable post | Open/Close All Comments


Add A new comment
Name: (Register)
Email: (optional)
Quick HTML: (help)
  Close current tag   Standard Mode
  Close all tags   Enhanced Mode
Comment:


Smilies
(help)
Parse URL's: (will automatically add [url] [/url] round the web addresses in your comment)