Google on Security Alert ?!!

Discussion in 'Google' started by abuzant, Jan 4, 2007.

  1. #1
    [FONT=Arial,Helvetica][SIZE=-2][FONT=Arial, Helvetica]Though the New Years holiday was a long vacation for many, it was a long work weekend for those in Google's security operations.

    [/FONT][/SIZE][/FONT] [FONT=Arial,Helvetica][SIZE=-2][FONT=Arial, Helvetica]Heather Adkins, information security manager at Google, said in a statement e-mailed to internetnews.com that over the holiday weekend Google was notified of a vulnerability that spanned multiple Google products.[/FONT][/SIZE][/FONT]
    [FONT=Arial,Helvetica][SIZE=-2][FONT=Arial, Helvetica]
    [/FONT][/SIZE][/FONT]
    [FONT=Arial,Helvetica][SIZE=-2][FONT=Arial, Helvetica]"We were first notified that this issue affected Google Video and fixed it within a few hours of receiving the report," Adkins stated. "We were then notified that the same issue affected other Google products. The problem with the other products was resolved within 24 hours of the second report. To our knowledge, no one exploited the vulnerability and no users were impacted."[/FONT][/SIZE][/FONT]
    [FONT=Arial,Helvetica][SIZE=-2][FONT=Arial, Helvetica]
    [/FONT][/SIZE][/FONT]
    [FONT=Arial,Helvetica][SIZE=-2][FONT=Arial, Helvetica]The vulnerability, if exploited, could have allowed Google users' Gmail contact lists and other information to be exposed to malicious attackers. Adkins noted that the vulnerability related to how Google uses certain JSON (JavaScript Object Notation) (define) object within some of its product code.[/FONT][/SIZE][/FONT]
    [FONT=Arial,Helvetica][SIZE=-2][FONT=Arial, Helvetica]
    [/FONT][/SIZE][/FONT]
    [FONT=Arial,Helvetica][SIZE=-2][FONT=Arial, Helvetica]A flaw was reported and fixed over the weekend, and there are allegations in the wild that a new crop of security issues may still exist.

    Source:
    http://www.intranetjournal.com/articles/200701/ij_01_04_07a.html

    JFYI: Ruslan
    [/FONT][/SIZE][/FONT]
     
    abuzant, Jan 4, 2007 IP
    GTech likes this.
  2. sgugal

    sgugal Peon

    Messages:
    183
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #2
    That's good to hear that they fixed it so fast :)
     
    sgugal, Jan 4, 2007 IP
  3. abuzant

    abuzant Well-Known Member

    Messages:
    956
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    140
    #3
    i am still actually digging here and there to find more information what exactly was wrong.. will post in case i figure out anything :D
     
    abuzant, Jan 4, 2007 IP
  4. ablaye

    ablaye Well-Known Member

    Messages:
    4,024
    Likes Received:
    97
    Best Answers:
    0
    Trophy Points:
    150
    #4
    Interesting. Even Google has vulnerabilities. Good to know :D
     
    ablaye, Jan 4, 2007 IP
  5. abuzant

    abuzant Well-Known Member

    Messages:
    956
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    140
    #5
    they probably decided to start using Milkosoft software somewhere.. and here cam the vulnerability :D
     
    abuzant, Jan 4, 2007 IP