Google Blogoscoped

Forum

Google antiphishing site exposes private user data

Juha-Matti Laurio [PersonRank 10]

Monday, January 22, 2007
17 years ago2,649 views

This was expected to happen, sooner or later:

"The login information was contained in 15 URLs submitted through Google's Firefox toolbar, which lets users report Web pages they suspect to belong to phishing sites."

The good news is that
"Google said it also has implemented a mechanism that detects when a submitted URL contains login data and prevents that information from getting posted to the list."

An interesting screenshot of sample data included to InfoWorld article as well. Personal information removed with black boxes by the Finjan, company behind the discovery:
http://www.infoworld.com/archives/emailPrint.jsp?R=printThis&A=/article/07/01/22/HNgooglephishing_1.html

TOMHTML [PersonRank 10]

17 years ago #

I saw the file. 15 URL on hundreds. And when they said "login information", more than an half was just a parameter "&token="...
Much buzz for nothing really serious.

Ionut Alex. Chitu [PersonRank 10]

17 years ago #

I read about this on Google Bad News, err TechCrunch.

Tony Ruscoe [PersonRank 10]

17 years ago #

<< And when they said "login information", more than an half was just a parameter "&token="... >>

I saw this file recently before Google had been informed and many of the URLs had "username=" and "&password=" in the query strings.

TOMHTML [PersonRank 10]

17 years ago #

many, many... I don't think so. A really small percentage of the URL. And I think user changed their passwords after that, no?

Tony Ruscoe [PersonRank 10]

17 years ago #

Well, that depends how you define "many" I guess. And I'm not sure whether the users changed their passwords... ;-)

Ionut Alex. Chitu [PersonRank 10]

17 years ago #

OK, so if I give you this URL:
greatsite.com/nice.php?u=coolstuff&kk=78
&ps=verynice&borl=8yy9iyi7tu

would you guess that coolstuff is a Gmail ID and 8yy9iyi7tu is the password?

Ionut Alex. Chitu [PersonRank 10]

17 years ago #

Check the results for this query:
http://www.google.com/search?hl=en&lr=&client=firefox-a&rls=org.mozilla%3Aen-US%3Aofficial&hs=zNd&as_qdr=all&q=allinurl%3A+password+gmail.com&btnG=Search

Juha-Matti Laurio [PersonRank 10]

17 years ago #

One of the sample URL' is
.../.boa/online_banking.html?AccessID=[removed by Finjan]...

It appears that user has enter his or hers credentials and submitted the URL to Google's database after this. Everything is possible in today's world.

Forum home

Advertisement

 
Blog  |  Forum     more >> Archive | Feed | Google's blogs | About
Advertisement

 

This site unofficially covers Google™ and more with some rights reserved. Join our forum!