{"id":314,"date":"2005-10-11T20:27:08","date_gmt":"2005-10-11T13:27:08","guid":{"rendered":""},"modified":"2005-10-11T20:27:08","modified_gmt":"2005-10-11T13:27:08","slug":"google-fixes-web-site-security-bug","status":"publish","type":"post","link":"https:\/\/deepquest.code511.com\/blog\/2005\/10\/google-fixes-web-site-security-bug\/","title":{"rendered":"Google fixes Web site security bug"},"content":{"rendered":"<p>Google has fixed a security flaw on its Web site that opened the door to phishing scams, account hijacks and other attacks, security researchers said Monday.<\/p>\n<p>The flaw, known as a cross-site scripting vulnerability, existed on the Web site for Google&#8217;s AdWords advertising program and a customer training site, according to security company Finjan Software, which discovered the problem.<!--more--><\/p>\n<p>Attackers could have exploited the flaw to hijack Google accounts, launch phishing scams or even download malicious code onto users&#8217; computers, according to Finjan. Phishing scams are designed to trick people into giving up sensitive information such as usernames, passwords, credit card details and Social Security numbers.<\/p>\n<p>Finjan informed Google of the bug late last month, and the problem was fixed within 30 hours, said Limor Elbaz, a vice president at Finjan, which is headquartered in San Jose, Calif. &#8220;Google&#8217;s responsiveness was very good,&#8221; she said.<\/p>\n<p>Google confirmed that it was alerted &#8220;a little while ago&#8221; and fixed the flaw. &#8220;No user data was compromised, and we applaud Finjan for following industry best practices for vulnerability disclosure,&#8221; a Google representative said in an e-mailed statement.<\/p>\n<p>The security problem existed because forms on Google&#8217;s Web site did not validate and filter data entered into certain fields. This allowed an attacker to inject extra content and scripts that would run on the user&#8217;s computer, according to Finjan. To take advantage of the flaw, an attacker would have to craft a special Web link and trick the user to follow it.<\/p>\n<p>&#8220;The dangerous thing in the case of Google is that the link would look like an innocent Google link,&#8221; Elbaz said.<\/p>\n<p>more from [url=http:\/\/news.com.com\/Google+fixes+Web+site+security+bug\/2100-1002_3-5892525.html?tag=nefd.top]News.com[\/url]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google fixes Web site security bug<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-314","post","type-post","status-publish","format-standard","hentry","category-security"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4bBYZ-54","_links":{"self":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/314","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/comments?post=314"}],"version-history":[{"count":0,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/314\/revisions"}],"wp:attachment":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/media?parent=314"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/categories?post=314"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/tags?post=314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}