Google won't fix login page flaw that can lead to malware download

    Google won't fix login page flaw that can lead to malware download


    Posted: 30 Aug 2016
    Google has said it will not fix a potential security flaw that could trick a user into downloading malware from its login window.

    The company told security researcher Aidan Woods it "made the decision not to track" his bug bounty submission as a vulnerability.

    Woods explained on his blog that Google's login screen allows an app or service to redirect to a page after the user signs in.

    The theory goes that an attacker could trick a user into clicking a link that points to a malware file.

    But Google said that the redirect page has to fall within "*google.com" domains, limiting its impact.

    The problem, said Woods, is that malware hosted on "drive.google.com" or "docs.google.com" which fall within the Google subdomain parameters could still be used to serve up malware, and hide it as a genuine Google login page.

    The search giant said in its reply to Woods: "Only first reports of technical security vulnerabilities that substantially affect the confidentiality or integrity of our users' data are in scope, and we feel the issue you mentioned does not meet that bar."

    Woods, believing Google didn't fully understand the issue, published the full exchange of emails on his blog.


    Source: Google won't fix login page flaw that can lead to malware download | ZDNet

    See also: Aidan Woods - Google's Faulty Login Pages
    Brink's Avatar Posted By: Brink
    30 Aug 2016



  1. Posts : 20,583
    Win-7-Pro64bit 7-H-Prem-64bit
       #1

    I feel all harm and fuzzy inside :)
    I never understood the page switching part of a login
    I always thought is a silly thing to do personally.
      My Computer


  2. Posts : 1,167
    W10 32 bit, XUbuntu 18.xx 64 bit
       #2

    ThrashZone said:
    I feel all harm and fuzzy inside :)
    I never understood the page switching part of a login
    I always thought is a silly thing to do personally.

    Facebook does it to, when you comment on a news article that use facebook connect.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 22:32.
Find Us