Google Toolbar Input Validation Hole

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Google Toolbar Input Validation Hole

Post by Tami »

Google Toolbar Input Validation Hole in 'About' Page Lets Local Users Execute Scripting Code

SecurityTracker Alert ID: 1011351
SecurityTracker URL: [url=\"http://securitytracker.com/id?1011351\"]http://securitytracker.com/id?1011351[/url]

Updated: Sep 19 2004

Original Entry Date: Sep 17 2004

Impact: Execution of arbitrary [url=\"http://www.securitytracker.com/archives/impact/143.html\"]code[/url] via local system, User access [url=\"http://www.securitytracker.com/archives/impact/23.html\"]via[/url] local system

Exploit Included: Yes

Version(s): Tested on 2.0.114.1-big/en (GGLD)

Description: Viper reported an input validation vulnerability in the Google Toolbar. A local user can execute arbitrary scripting code.

It is reported that the 'About' section of the Google Toolbar does not properly filter HTML code. A user can create HTML that, when loaded by the target user, will invoke the About page and execute arbitrary scripting code in the context of the page.

A demonstration exploit is provided:

<s c r i p t>
window.showModalDialog("res://C:\\Program%20Files\\Google\\GoogleToolbar1.dll/ABOUT.HTML",
"<div style=\"background-image:
url(java script:alert(location.href));\">");
</s>

Rafel Ivgi subsequently reported that the 'res:' protocol cannot be invoked from the Internet zone, preventing this flaw from being directly exploitable by remote users.

Impact: A user can cause scripting code to be executed in the Local Computer security zone.

Solution: No solution was available at the time of this entry.

[url=\"http://www.securitytracker.com/alerts/2004/Sep/1011351.html\"]source[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”