Google Public Service Search Makes for Easy Phishing 40
lisah writes "According to reports at NewsForge this morning, Developer Eric Farraro has discovered a potential hole in Google's Public Search Service that may leave the door wide open for phishing scams. The Public Search Service, designed to allow universities and other non-profit institutions to add Google search capabilities to their websites, provides code that allows website developers to customize the header and footer of the search results page. Handy (and malicious) coders can manipulate the headers and footers to create what looks like a Google sign-in page and then collect the login names and passwords of unsuspecting users." NewsForge and Slashdot are both owned by OSTG.
report them (Score:1, Funny)
Article notes... (Score:1)
Re:Article notes... (Score:4, Informative)
Give a man a fish... (Score:4, Funny)
(Sigh) Its all rather depressing realy. After having the same domain and email address for ten years my spam to real mail ratio is about 500:1 and I can find my email address on decade old usenet posts via Google.
Re:Give a man a fish... (Score:4, Funny)
Build a man a fire and keep him warm for a night. Set a man on fire and you will keep him warm for the rest of his life.
Any major web service has this non-issue (Score:2, Insightful)
Of course (Score:2)
Personally, I think it's going to get so bad that all online commerce is going to grind to a halt either because of scared customers, or because companies' litigation costs.
Re: (Score:2)
> agency that can do anything about it.
_Will_ do anything about it.
Not a google issue... (Score:1, Interesting)
Re:Not a google issue... (Score:5, Insightful)
Re: (Score:1)
Re: (Score:1, Informative)
Re:Not a google issue... (Score:5, Insightful)
Re: (Score:2, Interesting)
This is really bad. I hope google put this s
Try the address.... (Score:3, Insightful)
People always are looking for new ways to get user/pass from unsuspecting users. The internet is used to hurt the ignorant. I just hope I wont fall into such a good looking trap.
Re: (Score:1)
Wonder if Google has a cache of the page for us to look at.
I love you, Gooooogle (Score:3, Funny)
And you find that the google www.google.com/u/gplus doesnt work now. I'll say one thing. They sure are quick.
How the hell did they manage that gazillion man hours work of disabling a webpage & then testing the fix
of disabling the webpage so quickly.
I bet everyone right from the top to botton at Google must have been working non-stop on
disabling this webpage.
Anyway, Kudos & three cheers to Google on disabling this so quickly.
They surely are amazing. Who knows, maybe they even hired a few thousand ext
We're spoiled (Score:1)
I'm sorry for bringing this eternal FOSS-theme into the picture, but as Google is pretty involved in the FOSS community, they know that
Re: (Score:2)
I think the implied point of the parent post is that there are companies which would not (and apparently do not) respond so quickly. At least, this is the perception, judging by comments [slashdot.org] in other
So, it's really a comment about the apparent level of Google's bureacracy (i.e., not as bad as some), not their technical expertise. Of course, that's really just a comment about how bad other companies are perceived to be with regards to
Original post (Score:4, Informative)
Site in question [google.com]
It looks like the page has been replaced with a message warning about viruses and spyware. I looked at the page earlier (from Reddit.com) and the login page looked very legit--scary indeed.
If you put in a username and password, he didn't store it but he echoed it back to your browser. Even though he didn't store it, my concern was that the password was still being transmitted via plaintext...
Re: (Score:2)
So. Which of these exactly is Slashdot: a computer virus, or a spyware application?
I favor the "virus" analogy.
Ackbar'ed (Score:5, Funny)
National Google Alert (Score:2)
I rank Zonk at +4 [asleep at the wheel].
If you look closely, you will notice I wasnt being negative.
Re: (Score:2)
Won't happen again. Today.
Screw up of Google (Score:5, Insightful)
Google certainly does not do evil, but it is not exactly catching in the rye.
Re: (Score:1)
If only... (Score:1)
Porn from the Smithsonian Institute (Score:1)
to rephrase this (Score:2, Funny)
Eric Farraro has discovered that phishing might exist...
Re: (Score:1)
Bad habits (Score:2, Insightful)
the shiny lock is no guarantee (Score:1)
What about using js to grab cookies? (Score:2, Insightful)
Re: (Score:2)
The Death of Google Adsense (Score:1)