Google Desktop search flaws fixed

By Candace Lombardi on 22 February 2007

Tags: fix | flaw | google | google desktop | search | watchfire | vulnerable

update Several flaws in the popular Google Desktop software that could open PCs to intruders and possible data theft have been fixed.

The search giant has released patches for the issues, which were reported by Watchfire in a paper (PDF version) published on Wednesday. One of the problems is a cross-site scripting flaw that could let an outsider look through files on a compromised machine.

Google Desktop applies the same technology found in Google's search engine to let users try to find items on their PC and on shared networked computers. The tool indexes and combs through e-mails, documents and files on the user's PC and stores Web pages as part of its approach.

Hackers could use cross-site scripting to manipulate Google Desktop's functionality for their own ends, said Danny Allan, director of security research at Watchfire. The desktop application's integration with Google Search, Google's public Internet search application, is a weak spot, he added. It means that the vulnerabilities found by Watchfire could have been exploited without the attack being detected by information protection systems, antivirus software and firewalls, he said.

Such an attack is different from traditional ones, because it relies on JavaScript code, rather than the insertion of binary code, to control Google Desktop. It uses the application remotely to search for confidential information, according to Watchfire's report.

That means that passwords and banking information stored either in computer files or in Web page history could be accessed remotely by the attacker, Allan said.

Watchfire notified Google on January 4 of three vulnerabilities and one architectural flaw in the application, Allan said. Google responded to the security company on February 1 and asked for a few weeks before Watchfire went public with the information. The search giant has issued a patch for the problems.

"A fix was developed quickly, and users are being automatically updated with the patch," Google said in a statement. "In addition, we have another layer of security checks to the latest version of Google Desktop to protect users from similar vulnerabilities in the future."

The search company recommends that people make sure they are running the most recent version of Google Desktop.

It does not appear that anyone actually took advantage of the vulnerabilities and made attacks on Google Desktop users, both Watchfire and Google said.

However, Google Desktop is still vulnerable to these cross-site scripting attacks, Allan said, because of the "poor architectural decision" to include a link from Google Web servers to the Google Desktop user's PC.

"The three vulnerabilities were fixed. We also recommended to Google that if there was not a link between Google.com and my machine, then (the hacker) would not be able to connect to my computer. We believe they should remove that link or give consumers a choice as to whether someone can connect from the public Internet to their computer," Allan said.

The link enables a feature that places "Desktop" as one of the choices above the Google homepage search bar, alongside choices like "Images" and "News," once a user has downloaded Google Desktop. It allows Google Desktop users, no matter which browser they are in, to switch between searching the Internet and searching their computer from the Google home page, according to the Watchfire report.

"If another vulnerability is found within Google Desktop, then the same devastating things could happen," Allan said.

Allan likened the architectural link to the Internet to a swinging screen door. It's fine for it to swing out so that I can get out there, but it should not be allowed to swing back in, he said.

Like this article? Click below to send it to your mobile for free!

karen zavasnik
24/02/2007 01:19 AM

Google needs to improve on the user's page for better news reporting and graphic's..Where are your pictures? Earthlink, MSN, yahoo, etc do a better job. I use my earthlink browser as it search the internet better and offers so much more. Plus where does google put my spam or suspect e-mail???

Report offensive content

ibaa
03/01/2008 10:07 PM

I do not know what to say

Report offensive content

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • Gmail gets colourful themes

  • Kevin Rudd joins Twitter

  • Gmail gets voice, video chat

  • Google, Telstra sign deal for Yellow Maps

  • Sensis kills its search, uses Google

  • Oi!: MTV Music is, like, the raddest thing ever

  • Britney arrives on Twitter

  • Oi!: An end to drunken, embarrassing emails?

  • Adobe Dreamweaver CS4

More articles »

Find the right software

Brand
  • Multiple options can be selected

    • Adobe Dreamweaver CS4

      Adobe Dreamweaver CS4

      Designers and editors who lean on Dreamweaver for complex dynamic websites will find plenty of tweaks and improvements in version 4.

    • Chrome (beta)

      Chrome (beta)

      Google has rethought the Internet browser — some of its basic underpinnings are quite novel — but users will recognise some features as they exist in other, open-source browsers on the market today.

    • Internet Explorer 8 Beta 2

      Internet Explorer 8 Beta 2

      Microsoft's release should retain its browser base but doesn't yet have enough to lure loyal Firefox users back to Internet Explorer.

    • MobileMe

      MobileMe

      MobileMe is the successor to .Mac, Apple's subscription service for publishing photos and other personal content to the Web.

    • Firefox 3

      Firefox 3

      If only for the speed, lightness of being and security alone, Firefox remains our Editors' Choice for best internet browser.

    More reviews »

    Membership benefits

    Create wishlists

    Create wishlists

    See a product on CNET Australia that you want? Add it to your wishlist and send a hint to your friends and family. Sign up for a free CNET Australia membership now!