Google Expose: Protect Yourselves!
By:
Minu Sirsalewala
| Jan 22,2007
Finjan, a provider of proactive web security solutions for businesses and organizations, reconfirmed recent reports that Google has unwittingly exposed private user names and passwords on the Google anti-phishing blacklist, which did not use any access protection.
Finjan belives that such sensitive information could potentially have been used to compromise user privacy, and could even have been used for identity theft or financial profit (as users generally have a single "web" password for most of their online accounts).
On January 3, 2007, Finjan's Malicious Code Research Centre (MCRC) researchers discovered that a list of URLs was available and unprotected on Google's servers and immediately informed Google, which acknowledged receipt of the alert about the vulnerability.
Finjan believes the information on the servers had been gathered using Google's anti-phishing browser extension and it has notified all affected users. Recent tests conducted by Finjan confirm that there is no data leakage on the current Google anti-phishing blacklist.
"Finjan became aware of the problem after examining a publicly available list of URLs provided from Google's servers," said Yuval Ben-Itzhak, Finjan's chief technology officer. "Finjan found that sensitive user information was available on the web with no access protection, including e-mail, user names, passwords and session tokens that could be used by hackers to compromise users' privacy."
Finjan warns enterprises that they must minimize the risk of exposing confidential information from similar web applications. Finjan recommends that users make sure that they have proactive protection in their web security solution.
Users are also recommended to check their vendor's research capabilities and their ability to provide up-to-date information which is immediately translated it into actionable security measures.
Finally, Finjan recommends that users examine their egress data policy to make sure that they cover all known and suspicious site access.
Finjan belives that such sensitive information could potentially have been used to compromise user privacy, and could even have been used for identity theft or financial profit (as users generally have a single "web" password for most of their online accounts).
On January 3, 2007, Finjan's Malicious Code Research Centre (MCRC) researchers discovered that a list of URLs was available and unprotected on Google's servers and immediately informed Google, which acknowledged receipt of the alert about the vulnerability.
Finjan believes the information on the servers had been gathered using Google's anti-phishing browser extension and it has notified all affected users. Recent tests conducted by Finjan confirm that there is no data leakage on the current Google anti-phishing blacklist.
"Finjan became aware of the problem after examining a publicly available list of URLs provided from Google's servers," said Yuval Ben-Itzhak, Finjan's chief technology officer. "Finjan found that sensitive user information was available on the web with no access protection, including e-mail, user names, passwords and session tokens that could be used by hackers to compromise users' privacy."
Finjan warns enterprises that they must minimize the risk of exposing confidential information from similar web applications. Finjan recommends that users make sure that they have proactive protection in their web security solution.
Users are also recommended to check their vendor's research capabilities and their ability to provide up-to-date information which is immediately translated it into actionable security measures.
Finally, Finjan recommends that users examine their egress data policy to make sure that they cover all known and suspicious site access.
| Ads by Google | ||
Post a Comment on “Google Expose: Protect Yourselves!”
LATEST NEWS
- Proteans Opens Fourth Development Centre In Bangalore
- Superfil Selects SYSTIME For Oracle EBS Implementation
- Cisco To Enhance SMB Tech Investments With Flexi-Pay Options
- HP Bets Big On SMBs
- Nuance Launches 9 Indian Languages For Speech Recognition
- NeoAccel Announces VMware Version Of SSL VPN-Plus
- APEJ Manufacturers To Display Strong Demand For IT Services
- Experian QAS Launches SaaS Offering For Contact Data Mgmt
- India, Japan To Be Largest Regional WiMAX Markets By 2012
- Customer Focus Differentiates IT Leaders From The Rest
| Ads by Google | ||
RELATED
| Ads by Google | ||
Hot Searches & Keywords :
APAC
Acquisition
Asia Pacific
Asian Paints
BFSI
BI
BSNL
Bangalore
Bharti Airtel
Blackberry
Broadband
Business
Business Objects
Business intelligence
CA
CIO
CIOs
CRM
Cisco
Cisco Systems
Compliance
Data
Data Centre
Datacentre
Dell
EMC
ERP
Frost & Sullivan
Gartner
Google
Growth
HP
IBM
IDC
IT
India
Innovation
Intel
Internet
Linux
Manish Choksi
McAfee
Microsoft
Mobile
Mobile Banking
Nasscom
NetApp
Network
Novell
Open Source
Oracle
PLM
Red Hat
Retail
SAP
SMB
SMBs
SME
SMEs
SOA
SaaS
Satyam
Security
Servers
Software
Storage
Sun Microsystems
Symantec
TCS
Unified Communications
VMware
Virtualisation
VoIP
Web
Web 2.0
Websense
WiMax
Wipro
e-governance
healthcare
investment
outsourcing
partnership
telecom
|
|
||
| Ads by Google |
Sections
Applications |
Audits&surveys |
Bfsi |
Bookreviews |
Businessintelligence |
Businessprocesses |
Ciscosmenews |
Ciscowhitepapers |
Computing |
Contactcenters |
Contributedvideos |
Crm |
Ctoprofiles |
Datasecurity |
Databases |
Datacenters |
Education |
Energy |
Erp |
Focusspecials |
Government |
Guruspeak |
Hardwaresecurity |
Indialogue |
Innovation&leadership |
Innovators |
Intrusiondetection |
Intrusionprevention |
Ites |
Knowledgeprocess |
Lenovo |
Linux |
Managedservices |
Manufacturing |
Media |
Mobile |
Mobility |
Movement |
Networking |
Oncuewithitleaders |
Peoplemanagement |
Pharma |
Platforms |
Policies&compliance |
Recruitment |
Retail |
Saas |
Scm |
Securitymanagement |
Servers |
Services |
Softwaresecurity |
Softwareservices |
Specialreports |
Storage |
Storagesolution(apps) |
Techaction |
Telecom |
Telecommunications |
Theinsider |
Trendwatch |
Web |
Webisodescisco |
Weeklywrapup |
About Us | Copyright © 2006, Biztech2.com India - A Network18 Venture

