Hi, and welcome to CurEvents.com! This is a search-engine-friendly archive page.
Please click here to go to the main forum. Thanks.




Google



PDA

Click Here to View the Full Version with Images: Flaw in Google Desktop Search exposed data


pentachris
12-21-2004, 01:57 PM
I've never thought this software was a good idea; the security hole doesn't surprise me in the least. -Chris

http://www.newscientist.com/article.ns?id=dn6821

A flaw in Google's desktop search program was revealed on Monday by a team of computer researchers. They showed it could be used to capture valuable personal information from a remote user's computer.

Google Desktop Search (GDS) lets users quickly hunt for files and documents stored on their computer using a web browser. After installation, the program runs in the background - indexing documents, emails, instant messaging conversations and web browser history - so that searches bring up results almost instantly.

.....

By analysing packets of information sent across a network, the team realised they could fool the application into handing over desktop search results to a remote user via the internet.

.....

The trick is more a proof of concept than a real threat as Google was notified of the vulnerability in November and began updating desktop programs remotely on 10 December. The company said in a statement that it had "since fixed the problem so that all current and future users are secure".

Bruce Schneier, a US computer security expert, said the flaw is potentially serious but no different to those found in many different applications every day. "Like any piece of commercial software, it's huge and complex," he told New Scientist.

Larred
12-21-2004, 02:35 PM
Interesting, I agree with your assessment Chris.

nanna
12-21-2004, 03:40 PM
(snip from Dow Jones Newswires, sorry no link)

2:55 (Dow Jones) A new computer worm is attacking and vandalizing tens of
thousands of Web sites by looking up potential new victims through Google
(GOOG). The "Santy" worm, as it has been named by security firms, has
compromised at least 38,000 computers since it first appeared on the Internet
on yesterday, according to iDefense Inc., a computer-security intelligence
firm. As it spreads it leaves behind this message on victim sites: "'This site
is defaced!!!' NeverEverNoSanity." The worm searches Google to find sites that
use flawed versions of open-source Web bulletin-board language phpBB. (RTR)


Is this related?


nanna

Aleph Null
12-21-2004, 03:45 PM
I don't think it is related, nanna. (Shouldn't be a concern for this board either, as we use different software.)

a0