Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Product Tips & Reviews
Daily Downloads
Daily Technology News
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: GoogleWeb ServicesWeb-based Applications

Google Toolbar Flaw Opens Door for Phishers

Robert McMillan, IDG News Service

Tuesday, December 18, 2007 4:30 PM PST
Recommend this story?

Google is working to fix a bug in the Google Toolbar that could allow criminals to steal data or install malicious software on a system, a security researcher warned Tuesday.

The flaw lies in the mechanism Google Toolbar uses to add new buttons on the browser. Because the toolbar does not perform adequate checks when new buttons are being installed, a hacker could make his button appear as though it was being downloaded from a legitimate site when in fact it came from somewhere else. By spoofing the origin of the toolbar button, an attacker could download malicious files or launch a phishing attack against the victim, wrote security researcher Aviv Raff in a blog post on the issue.

Raff has posted proof of concept code, showing how such an attack would work with the Internet Explorer browser. A Google spokeswoman confirmed Tuesday that the company is working to fix the problem.

The attack requires many steps. First, the victim would have to be tricked into clicking on a Web link that would then pop up a window asking the user if he wants to install a custom button on his toolbar. Because of the flaw, this alert could look like it was downloading the button from a legitimate site such as Google.com, even if it were not. Once the button was installed on the toolbar, the victim would then have to click on it, and finally agree to download and run an executable file for the malicious software to be installed.

Because the user would have to go through so many steps in order to fall victim to the attack, the bug isn't a critical one, said Marc Maiffret, an independent security researcher. "While it is interesting, it's probably a low threat compared to other flaws out there," he said via instant message.

Still, it was sloppy work on Google's part to miss such a simple attack, he said. "They should definitely assess how it slipped through the cracks," he said.

This is not the first obvious Google flaw that Raff has found. Last month, he showed how a simple Web programming error on the Google.com Web site could allow attackers to launch what's known as a cross-site scripting attack.

Because Google's programmers didn't properly check the HTML generated by the Google search engine, Raff was able to create a specially crafted Google link that, when clicked by the victim, would trick the browser into running unauthorized scripting code. This type of link could be used to steal the victim's Google account or conduct phishing attacks, Raff said

This error was fixed by Google just hours after Raff notified the company of the problem, but a demo of the flaw being exploited can be seen online.


Recommend this story?
Related Searches: google toolbar bug browser phishing

Comments
Latest News
The One Laptop Per Child Project and Microsoft plan to make both Windows and Linux available on a version of the project's XO... 15-May-2008
Yahoo has responded to investor Carl Icahn's threat to take control of Yahoo's board and force it back to the negotiating... 15-May-2008
Billionaire investor Carl Icahn's proxy fight for Yahoo is aimed at reigniting merger talks between the Internet company and... 15-May-2008
When Apple ships its iPhone 2.0 update--and the accompanying App Store for distributing third-party software for the... 15-May-2008
Amit Singh thought something was missing from OS X. The Google engineer--and author of Mac OS X Internals--took a look at what... 15-May-2008
This week our readers engage on a wide range of topics, from software piracy to capitalism. 15-May-2008
Merger and acquisition news this week from Hewlett-Packard, EDS, Comcast, Plaxo, CBS and CNET -- along with Carl Icahn's... 15-May-2008
The industry momentum for data portability brotherhood hit a bump on Thursday when Facebook blocked Google's Friend Connect... 15-May-2008
The U.S. International Trade Commission (ITC) has voted to investigate complaints by two U.S. companies that 18 other... 15-May-2008
AT&T has begun restricting its sales of Apple's iPhone to one device per customer, according to employees at AT&T... 15-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)