All the latest UK technology news, reviews and analysis

Testers expose Google Desktop security bug

by Clement James

22 Feb 2007

Be the first to comment

  • Tweet this

Security experts have uncovered a vulnerability in Google Desktop which could enable a malicious hacker to achieve remote access to sensitive data and, in some conditions, full system control.

Web application security firm Watchfire claims to have uncovered a vulnerability which highlights the danger of integration between desktop and web-based applications.

The flaw could allow an attacker to escalate privileges by crossing from the web environment to the desktop application environment.

The vulnerability centres on integration between the Google.com site and Google Desktop, and Google Desktop's failure properly to encode output containing malicious or unexpected characters, the security firm said.

In the attack, researchers used malicious logic to act as a parasite, using JavaScript code to control Google Desktop functionality.

An attacker could evade current information protection systems, such as antivirus software and firewalls, allowing them to covertly hijack sensitive local information.

Google has issued a patch which mitigates the immediate risk of the attack, Watchfire said.

"Application security vulnerabilities need to be taken seriously," said Michael Weider, founder and chief technology officer at Watchfire.

"As the potential damage of a cross-site scripting attack against a desktop application with a web interface is enormous, web application security must be comprehensively evaluated and continually monitored.

"Industry leaders like Google continue to make strides in security but vulnerabilities can surface due to the dynamic nature of applications."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

32%

2%

15%

51%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Sales Consultant - Datacentre

Sales Consultant - Data Centre, Colocation, Hosting...

Senior Interaction Designer (User Experience, UCD, Prototypes)

Senior Interaction Designer (User Experience, UCD, Interactive...

Head of Information Architecture / UX - London - £370p/d

Information Architecture / IA / User Experience / UX...

Sales Consultant

Sales Consultant A rapidly expanding independent managed...

To send to more than one email address, simply separate each address with a comma.