Security Blog

The latest news and insights from Google on security and safety on the Internet

Do Know Evil: web application vulnerabilities

4 tháng 5, 2010
Share on Twitter Share on Facebook
Google

6 nhận xét :

H3dicho nói...

"it takes a hacker to catch a hacker,"

GREAT!!

lúc 12:05 4 tháng 5, 2010
vint cerf nói...

Sure this should be titled "Defense against the Dark Arts" at Bugwarts University?

vint

lúc 13:11 4 tháng 5, 2010
zprian nói...

When you create an account, the user and password are sent by GET method.
Maybe, would be better send credentials via a POST form to avoid shoulder-surfing.

lúc 03:54 5 tháng 5, 2010
JOHNinKEYWEST nói...

I had my wp blog hacked a while back with a script it was nasty. So this looks pretty interesting. I'm surprised it wasn't Jaiku :) I wonder why Google did work that site like they should of. Well anyway Google does many things I don't understand :) Thanks for the op to learn appreciate it

lúc 04:08 5 tháng 5, 2010
Unknown nói...

I think the lab skipped over bookmarklet attacks. You don't even need to create the link. The home page field could be set to javascript:alert("a"). When I first played around with the web app, I wasn't sure what the home page was (before I configured my account), and I clicked on the only two there.

Also, by having the user expect a link, you can easily make up a phishing scheme (you could use a javascript redirect to replace the page in web history with your own site, which the pretends to be a warning that you are about to leave the site. then you send the user to some boring site, prompting the user to hit the back button. then, thanks to a cookie or remembering the ip address, your fake page asks the user to log in again.)

lúc 21:31 20 tháng 5, 2010
The great nói...

There are many people stealing information and pasword.
please keep them away from doing it.
Thanks

lúc 05:13 29 tháng 10, 2010

Đăng nhận xét

  

Nhãn


  • #sharethemicincyber
  • #supplychain #security #opensource
  • android
  • android security
  • android tr
  • app security
  • big data
  • biometrics
  • blackhat
  • C++
  • chrome
  • chrome enterprise
  • chrome security
  • connected devices
  • CTF
  • diversity
  • encryption
  • federated learning
  • fuzzing
  • Gboard
  • google play
  • google play protect
  • hacking
  • interoperability
  • iot security
  • kubernetes
  • linux kernel
  • memory safety
  • Open Source
  • pha family highlights
  • pixel
  • privacy
  • private compute core
  • Rowhammer
  • rust
  • Security
  • security rewards program
  • sigstore
  • spyware
  • supply chain
  • targeted spyware
  • tensor
  • Titan M2
  • VDP
  • vulnerabilities
  • workshop


Archive


  •     2025
    • thg 1
  •     2024
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2023
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2022
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2021
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2020
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2019
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2018
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2017
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2016
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2015
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2014
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2013
    • thg 12
    • thg 11
    • thg 10
    • thg 8
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2012
    • thg 12
    • thg 9
    • thg 8
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
    • thg 1
  •     2011
    • thg 12
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 6
    • thg 5
    • thg 4
    • thg 3
    • thg 2
  •     2010
    • thg 11
    • thg 10
    • thg 9
    • thg 8
    • thg 7
    • thg 5
    • thg 4
    • thg 3
  •     2009
    • thg 11
    • thg 10
    • thg 8
    • thg 7
    • thg 6
    • thg 3
  •     2008
    • thg 12
    • thg 11
    • thg 10
    • thg 8
    • thg 7
    • thg 5
    • thg 2
  •     2007
    • thg 11
    • thg 10
    • thg 9
    • thg 7
    • thg 6
    • thg 5

Feed

Follow
Give us feedback in our Product Forums.
  • Google
  • Privacy
  • Terms