- Nokia's new N97 vs. the iPhone
- 10 Microsoft research projects
- Hard to get justice in MySpace case
- Smartphone smackdown: Storm vs. iPhone
- Apple removes antivirus support page
Google has patched security flaws in its Web site that would have exposed users to phishing and other attacks designed to steal account information, according to security researchers.
Researchers at risk management software company Watchfire posted an advisory this week about the flaws, which are called XSS, or cross-site scripting, vulnerabilities. These types of vulnerabilities leave a site open to various attacks, such as account hijacking, changing of user settings, cookie theft/poisoning or false advertising.
The advisory for the flaws can be found here .
The possibility for attacks at www.google.com was present when users encountered two different error pages, the "404 not found" error message and a Web-site redirection error message.
Google did not properly secure these pages, which exposed users to possible attack by exploiting the 7-bit Unicode Transformation Format character-encoding mechanism, according to Watchfire.
The company corrected the flaws by using character-encoding enforcement, according to Watchfire.
Google was not immediately available for comment Thursday.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment