Security Flaws Found in Google's Blogger
Patches are available to prevent hackers from taking control of Web logs.
Paul Roberts, IDG News Service
Pyra Labs patched a number of security holes in its Blogger Web-based publishing tool this week that could have enabled a hacker to publish thoughts on Web logs owned by others.
The holes were discovered by celebrated hacker Adrian Lamo, who reported them to Pyra, according to a statement on the Blogger Web site. Search engine company Google acquired Pyra in February for an undisclosed amount.
Three or four different vulnerabilities were discovered and reported to Pyra in January, Lamo said in an interview Friday.
Potential Problems
At least one of the vulnerabilities could have enabled a hacker to circumvent a process that prevented new users of Pyra's BlogSpot Web log hosting site from using the Web log address of an existing user, according to a report published on Symantec's SecurityFocus Web site.
By changing a hidden field in the user's Web browser to contain the address of an existing Web log, an attacker could replace that Web log with his or her own musings.
Lamo likened the process to reassigning an Internet domain name to a different Internet Protocol address.
Another security hole discovered by Lamo would have allowed hackers to add themselves to the list of those authorized to maintain a Web log, according to SecurityFocus.
The vulnerabilities affected the Web-based publishing tools that let Blogger users update their Web logs and could have been leveraged against Web logs hosted on Pyra's BlogSpot site or on domains maintained by the Web log's owner, Lamo said.
Growing Popularity
Given the growing popularity of Web logs hosted by journalists, celebrities, and pundits in recent years, the Blogger security holes take on new weight, creating the possibility that hackers could supplant the opinions of well-known personalities and opinion-makers with their own.
Pyra's acknowledgment said the problems reported by Lamo had been resolved.
"We have fixed the security issues and Blogger is better for it," the message read, in part.
Pyra also lavished praise on Lamo for reporting the problems to them before they were publicized, calling Lamo a "good guy hacker" and saying "Adrian rocks."
A review of the Blogger logs indicated that none of the problems reported by Lamo were exploited before being patched, Pyra said.
Common Problem?
The vulnerabilities in Pyra's Blogger products were not unique to the company, which has "generally sound" technology and took a number of steps to prevent Web logs from being hijacked, according to Lamo.
Rather, the problem is common to many online services that require users to enter data in a number of different stages, for example, when creating or modifying account information, he said.
While checks to validate unique information like an e-mail address or log-in name may be performed at step one, they are rarely rechecked later in the registration process. That design flaw could enable hackers or even savvy users to modify cached account information and effectively hijack existing accounts, according to Lamo.
In addition to Web logs, similar vulnerabilities might be used to take over online property such as log-ins at major Internet service providers, Lamo said.
"It's something I've seen more times than I can count. Hidden form fields are just one example. It's a common problem in the way people think when they are designing complex systems," Lamo concluded.
Laptop Showcase
Mobile Computing
Featured APC Accessories
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
People who read this also read:
Best Prices on Antivirus Software
Norton Antivirus 2010 (Full Product, 1 User)Price: $17.90
Norton AntiVirus 2009 (Full Product)Price: $15.72
Norton Antivirus 2010 (Full Product, 1 User)Price: $16.95
Anti-virus 2010 (OEM Product, 1 User)Price: $17.95
Anti-Virus 2009 (Full Product)Price: $17.00
Norton Antivirus 2010 (Full Product, 3 Users)Price: $37.00
- 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
- A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage








