<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; google-desktop-flaw</title>
	<atom:link href="http://www.darknet.org.uk/tag/google-desktop-flaw/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Serious XSS Flaw in Google Desktop Allows Data Theft</title>
		<link>http://www.darknet.org.uk/2007/02/serious-xss-flaw-in-google-desktop-allows-data-theft/</link>
		<comments>http://www.darknet.org.uk/2007/02/serious-xss-flaw-in-google-desktop-allows-data-theft/#comments</comments>
		<pubDate>Thu, 22 Feb 2007 07:55:49 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[cross-site-scripting]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[google-desktop]]></category>
		<category><![CDATA[google-desktop-flaw]]></category>
		<category><![CDATA[google-desktop-vulnerability]]></category>
		<category><![CDATA[hacking-google]]></category>
		<category><![CDATA[hacking-google-desktop]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/02/serious-xss-flaw-in-google-desktop-allows-data-theft/</guid>
		<description><![CDATA[Google has fixed a security flaw in its desktop search software that created a means for hackers to rifle through personal files on users&#8217; PCs. A failure in Google Desktop to &#8220;properly encode output containing malicious or unexpected characters&#8221; created a means for hackers to cross from the web environment to the desktop application environment. [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Google has fixed a security flaw in its desktop search software that created a means for hackers to rifle through personal files on users&#8217; PCs.</p>
<p>A failure in Google Desktop to &#8220;properly encode output containing malicious or unexpected characters&#8221; created a means for hackers to cross from the web environment to the desktop application environment.</p>
<p>So if you are running Google Desktop we suggest you update it ASAP.</p>
<blockquote><p>The attack, outlined in a paper (<a href="http://www.watchfire.com/resources/Overtaking-Google-Desktop.pdf">PDF</a>) released by the firm, uses a cross-site scripting (XSS) flaw in the Google Desktop application in conjunction with any other XSS flaw in the Google.com domain to install malicious JavaScript on the user&#8217;s computer. Using the technique, an attacker could create a JavaScript program that Google Desktop repeatedly runs, allowing the attacker to search a victim&#8217;s computer using terms most likely to dredge up interesting data.</p>
<p>Google released an updated version of Google Desktop that fixes the local cross-site scripting flaw earlier this month, but many users may not have gotten the patch, said Danny Allan, director of security research for Watchfire. Because of the popularity of Google Desktop, there could be a large number of users with vulnerable systems.</p></blockquote>
<p>Read More:</p>
<p></p>
<p><a href="http://www.securityfocus.com/news/11443?ref=rss">Google Desktop flaw allows data theft</a><br />
<a href="http://www.theregister.co.uk/2007/02/21/google_desktop_search_bug/">Google patches critical desktop flaw</a><br />
<a href="http://blog.washingtonpost.com/securityfix/2007/02/serious_flaw_in_google_desktop.html">Serious Flaw in Google Desktop Prompts Patch</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Serious+XSS+Flaw+in+Google+Desktop+Allows+Data+Theft+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D489+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/02/serious-xss-flaw-in-google-desktop-allows-data-theft/&amp;t=Serious+XSS+Flaw+in+Google+Desktop+Allows+Data+Theft" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/02/serious-xss-flaw-in-google-desktop-allows-data-theft/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/02/serious-xss-flaw-in-google-desktop-allows-data-theft/&amp;title=Serious+XSS+Flaw+in+Google+Desktop+Allows+Data+Theft" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/02/serious-xss-flaw-in-google-desktop-allows-data-theft/&amp;title=Serious+XSS+Flaw+in+Google+Desktop+Allows+Data+Theft" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/02/serious-xss-flaw-in-google-desktop-allows-data-theft/&amp;title=Serious+XSS+Flaw+in+Google+Desktop+Allows+Data+Theft" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/02/serious-xss-flaw-in-google-desktop-allows-data-theft/&amp;title=Serious+XSS+Flaw+in+Google+Desktop+Allows+Data+Theft" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F02%2Fserious-xss-flaw-in-google-desktop-allows-data-theft%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/02/serious-xss-flaw-in-google-desktop-allows-data-theft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

