Overtaking-Google-Desktop-Google.com的跨站代码漏洞

Using a cross-site scripting vulnerability on Google.com in combination with an installed Google Desktop program, web app security consultants Watchfire were able to overtake a user’s computer and transmit sensitive local information to their own server. According to AP, Google was alerted to the vulnerability on January 4th, 2007, and in return alerted Watchfire of their fix on February 1st. (Google Desktop is automatically updated so if you have GD installed, you don’t need to do anything to patch this, Google says.)

你可能感兴趣的:(代码,Google,职场,休闲)