On TV.com: LOST Fans are Annoying
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dan Ilett
Posted on ZDNet News: Dec 20, 2004 3:52:00 PM

Google says it has fixed a flaw that could have allowed hackers to search the contents of PCs running the company's desktop search tool.

According to a statement issued Monday by the Web search company, it has rolled out a fix for the vulnerability. The flaw in the tool was discovered in late November by a Rice University computer scientist and two of his students.

A Google representative said, "We were made aware of this vulnerability with the Google Desktop Search software and have since fixed the problem so that all current and future users are secure."

Dan Wallach, an assistant professor of computer science at Rice University, discovered the vulnerability while working with graduate students Seth Fogarty and Seth Nielson. Wallach describes it as a composition flaw--where a security weakness is caused by the interaction of several separate components.

According to The New York Times, which first reported the discovery of the flaw, Wallach, Fogarty and Nielson found that the Google desktop tool looks for traffic that appears to be going to Google.com and then inserts results from a user's hard disk for a particular search.

They managed to trick the Google desktop search program into inserting those results into other Web pages where an attacker could read them. This would only work after a user had visited an attacker's Web site, upon which a Java program (as created by the Rice group) would be able to fool the Google desktop software into providing the user's search information. The program was able to do anything with the results, including transmitting them back to the attacking site.

The disclosure of this flaw comes just days after research company Gartner warned businesses to steer clear of Google's desktop search tool until a more robust, enterprise-ready version is released.

Security experts have also warned that virus writers could use desktop search tools to make their malware more efficient.

Dan Ilett and Graeme Wearden of ZDNet UK reported from London.

Google says it has fixed a flaw that could have allowed hackers to search the contents of PCs running the company's desktop search tool.

According to a statement issued Monday by the Web search company, it has rolled out a fix for the vulnerability. The flaw in the tool was discovered in late November by a Rice University computer scientist and two of his students.

A Google representative said, "We were made aware of this vulnerability with the Google Desktop Search software and have since fixed the problem so that all current and future users are secure."

Dan Wallach, an assistant professor of computer science at Rice University, discovered the vulnerability while working with graduate students Seth Fogarty and Seth Nielson. Wallach describes it as a composition flaw--where a security weakness is caused by the interaction of several separate components.

According to The New York Times, which first reported the discovery of the flaw, Wallach, Fogarty and Nielson found that the Google desktop tool looks for traffic that appears to be going to Google.com and then inserts results from a user's hard disk for a particular search.

They managed to trick the Google desktop search program into inserting those results into other Web pages where an attacker could read them. This would only work after a user had visited an attacker's Web site, upon which a Java program (as created by the Rice group) would be able to fool the Google desktop software into providing the user's search information. The program was able to do anything with the results, including transmitting them back to the attacking site.

The disclosure of this flaw comes just days after research company Gartner warned businesses to steer clear of Google's desktop search tool until a more robust, enterprise-ready version is released.

Security experts have also warned that virus writers could use desktop search tools to make their malware more efficient.

Dan Ilett and Graeme Wearden of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 29 Talkback(s)
fixed for current users
"We've fixed this for all future and current users."

It sounded (on Slashdot) like it was a combination of the way Google searched the web and the client, so they must have determined a server-side modification to be sufficient.

Write Google. Post back.... (Read the rest)
Posted by: smkatz Posted on: 12/26/04 You are currently: a Guest | | Terms of Use
All these new desktop search tools should be considered beta  Michael Kelly | 12/20/04
Why not stand-alone?  Roger Ramjet | 12/20/04
Google has a long way to go !!  thetruth_z | 12/20/04
Good Concept, but...  monteolsen@... | 12/20/04
Do I sense hypocrisy  TrueSpeak | 12/20/04
Well..  ExLax_in_the_BHind | 12/20/04
So what you're saying is...  PA-ITGuy | 12/20/04
we are talking baout beta software here...  linuxoverwindows | 12/20/04
im not prejudiced...  linuxoverwindows | 12/20/04
do current users need to do anything  daden | 12/20/04
you might care to dump it  benso | 12/20/04
Oh right, another ongoing nightmare, I see  benso | 12/20/04
youre on the right track  linuxoverwindows | 12/20/04
So, where's the patch?  Hey_Joe | 12/20/04
Exactly right...  Don Ellis | 12/20/04
Desktop search  thoseopps | 12/20/04
Google problems  davekinsey | 12/20/04
Hello-o-o...Netizens! Google Search is still in Beta Test  catgic | 12/20/04
a flaw is a flaw  PA-ITGuy | 12/20/04
and we all know...  linuxoverwindows | 12/20/04
google desktop  jpm007 | 12/20/04
US companies support Homeland Security, why won't you?  toomuchgreeatea@... | 12/20/04
Can you say CIA?  johnlb2002 | 12/20/04
the sky is falling, the sky is falling(NT)  Monkey_MCSE | 12/20/04
google  gselby4@... | 12/20/04
where is the patch?  Bruce Swanson | 12/20/04
spyware found it first  danarothrock@... | 12/20/04
Google flaw  libbynash@... | 12/21/04
fixed for current users  smkatz | 12/26/04

What do you think?

SmartPlanet

Click Here