Security Blog

The latest news and insights from Google on security and safety on the Internet

Do Know Evil: web application vulnerabilities

4. maj 2010
Share on Twitter Share on Facebook
Google

6 kommentarer :

H3dicho sagde ...

"it takes a hacker to catch a hacker,"

GREAT!!

4. maj 2010 kl. 12.05
vint cerf sagde ...

Sure this should be titled "Defense against the Dark Arts" at Bugwarts University?

vint

4. maj 2010 kl. 13.11
zprian sagde ...

When you create an account, the user and password are sent by GET method.
Maybe, would be better send credentials via a POST form to avoid shoulder-surfing.

5. maj 2010 kl. 03.54
JOHNinKEYWEST sagde ...

I had my wp blog hacked a while back with a script it was nasty. So this looks pretty interesting. I'm surprised it wasn't Jaiku :) I wonder why Google did work that site like they should of. Well anyway Google does many things I don't understand :) Thanks for the op to learn appreciate it

5. maj 2010 kl. 04.08
Unknown sagde ...

I think the lab skipped over bookmarklet attacks. You don't even need to create the link. The home page field could be set to javascript:alert("a"). When I first played around with the web app, I wasn't sure what the home page was (before I configured my account), and I clicked on the only two there.

Also, by having the user expect a link, you can easily make up a phishing scheme (you could use a javascript redirect to replace the page in web history with your own site, which the pretends to be a warning that you are about to leave the site. then you send the user to some boring site, prompting the user to hit the back button. then, thanks to a cookie or remembering the ip address, your fake page asks the user to log in again.)

20. maj 2010 kl. 21.31
The great sagde ...

There are many people stealing information and pasword.
please keep them away from doing it.
Thanks

29. oktober 2010 kl. 05.13

Send en kommentar

  

Etiketter


  • #sharethemicincyber
  • #supplychain #security #opensource
  • AI Security
  • android
  • android security
  • android tr
  • app security
  • big data
  • biometrics
  • blackhat
  • C++
  • chrome
  • chrome enterprise
  • chrome security
  • connected devices
  • CTF
  • diversity
  • encryption
  • federated learning
  • fuzzing
  • Gboard
  • google play
  • google play protect
  • hacking
  • interoperability
  • iot security
  • kubernetes
  • linux kernel
  • memory safety
  • Open Source
  • pha family highlights
  • pixel
  • privacy
  • private compute core
  • Rowhammer
  • rust
  • Security
  • security rewards program
  • sigstore
  • spyware
  • supply chain
  • targeted spyware
  • tensor
  • Titan M2
  • VDP
  • vulnerabilities
  • workshop


Archive


  •     2025
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2024
    • dec.
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2023
    • dec.
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2022
    • dec.
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2021
    • dec.
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2020
    • dec.
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2019
    • dec.
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2018
    • dec.
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2017
    • dec.
    • nov.
    • okt.
    • sep.
    • jul.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2016
    • dec.
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2015
    • dec.
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2014
    • dec.
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • jun.
    • apr.
    • mar.
    • feb.
    • jan.
  •     2013
    • dec.
    • nov.
    • okt.
    • aug.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2012
    • dec.
    • sep.
    • aug.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
    • jan.
  •     2011
    • dec.
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • jun.
    • maj
    • apr.
    • mar.
    • feb.
  •     2010
    • nov.
    • okt.
    • sep.
    • aug.
    • jul.
    • maj
    • apr.
    • mar.
  •     2009
    • nov.
    • okt.
    • aug.
    • jul.
    • jun.
    • mar.
  •     2008
    • dec.
    • nov.
    • okt.
    • aug.
    • jul.
    • maj
    • feb.
  •     2007
    • nov.
    • okt.
    • sep.
    • jul.
    • jun.
    • maj

Feed

Follow
Give us feedback in our Product Forums.
  • Google
  • Privacy
  • Terms