| |
|
|
|
|
 |
Please consider a small donation to help me keep this site running.
 |
|
| Recent Topics |
» What happens to things after 180 days?
by lindajean on Thu Nov 20, 2008 11:33 am
» EG Names Bonanzle 'The Best eBay Alternative We've Seen"
by purple_reading_giraffe on Thu Nov 20, 2008 11:32 am
» For FUN..Anyone up for a game of word association ??
by jimboyposting on Thu Nov 20, 2008 11:32 am
» I get crazy- feedback exchange legal?
by mone12345 on Thu Nov 20, 2008 11:29 am
» LOOK FOR THE NEW CONTEST TOMORROW
by SPORTSCARDS on Thu Nov 20, 2008 11:14 am
» eBid Officially Launches in US with Media Campaign
by purple_reading_giraffe on Thu Nov 20, 2008 11:13 am
» First self run shop
by safemode on Thu Nov 20, 2008 11:12 am
» Objective Comparison
by sciencefare on Thu Nov 20, 2008 11:01 am
» eBay Announced Improved PayPal Protection
by purple_reading_giraffe on Thu Nov 20, 2008 10:49 am
» Web retailers in U.S. are waging seasonal price wars
by dticorp on Thu Nov 20, 2008 10:39 am
|
|
|
 |
| Author |
Message |
elgato Location: TEXAS Total posts: 10003
|
Gadget lovers were dealt a blow on Wednesday when two researchers outlined what they called a "hole" during a Black Hat presentation.
"The attacker can forcibly install Google Gadgets; they can read the victim's search history once a malicious gadget has been installed in some specific circumstances; they can attack other Google Gadgets; they can phish usernames and passwords from victims, and so on," said Robert Hansen, also known as RSnake, a founder of security consultancy SecTheory. "Really, the sky is the limit, once the browser is under the control of an attacker. And that point is exacerbated by the fact that people trust Google be a trustworthy domain, making the attacks even easier."
Hansen said that users who are most vulnerable to attack are those who use Google and specifically Gmail since the Web-based e-mail service requires them to be logged in. The attack relies on users intentionally adding modules themselves; a user may be tricked into adding malicious Google modules to his iGoogle homepages. "These users are almost all using JavaScript and normal Web browsers, making them easing pickings for many different classes of attack, he added.
Tom Stracener, a senior security analyst at Cenzic and co-presenter of the talk, outlined the threat:
more.. link to news article |
|
_________________ http://www.elgatosden.com/
MODERATOR |
|
No rating |
|
 |
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
|  |
|
|
|