Watchfire Customer Login  Search  Japanese Language version
Products
AppScan Rational Policy Tester Fanatical Success Partners News & Events About Watchfire
News and Events

Watchfire Discovers Google Desktop Vulnerability That Hackers Could Exploit to Gain Full System Control

Web Application Security Leader's Researchers Demonstrate New Generation of Computer Vulnerabilities Based on Interaction Between Desktop and Web Applications

Watchfire

Sue Ann Wright

613.599.3888 ext. 4039

sueannw@ca.ibm.com

Schwartz Communications

Mike Schultz/Tim Whitman

781.684.0770

watchfire@schwartz-pr.com

- Web application security leader Watchfire, today announced its security researchers have discovered a vulnerability in Google Desktop which could enable a malicious individual to achieve not only remote, persistent access to sensitive data, but in some conditions full system control.

Initially discovered by Watchfire's Yair Amit the Company's security researchers have uncovered a new attack methodology that clearly emphasizes the danger of integration between desktop applications and Web based applications as an aperture for a malicious attacker to escalate his/her privileges by crossing from the Web environment to the desktop application environment. This outcome is the combined result of the integration between the Google.com Web site and Google Desktop, and Google Desktop's failure to properly encode output containing malicious or unexpected characters.

This attack, described in a new research paper describes how the malicious logic acts as a parasite, using JavaScript code to control Google Desktop functionality. While evading current information protection systems, such as anti-virus software and firewalls allowing the attacker to covertly hijack sensitive local information. (For example: Office documents, Media files, emails, in many cases, even deleted emails, chat sessions and files could be accessed.)

In this paper Watchfire details the methodology of attack and provides a valid use case including a description of the basic technique and some theoretical outcomes. Finally, Watchfire provides fix recommendations that are appropriate for Google Desktop, as well as for many other Web based applications. Google has been responsive and has issued a patch which mitigates the immediate risk of the attack.

"Application security vulnerabilities need to be taken seriously. As the potential damage of a Cross Site Scripting attack against a desktop application with a Web interface is enormous, Web application security must be comprehensively evaluated and continually monitored," said Michael Weider, founder and CTO, Watchfire. "Industry leaders like Google continue to make strides in security but due to the dynamic nature of applications vulnerabilities can surface."

Learn more about this attack including fix recommendations.

View a demonstration of the Google Desktop attack.

About Watchfire
Watchfire is the leading provider of web application vulnerability assessment software and the only company to offer an end-to-end solution including intelligent fix recommendations to evaluate, understand and resolve issues. More than 800 enterprises and government agencies, including AXA Financial, SunTrust, HSBC, Vodafone, Veterans Affairs and Dell rely on Watchfire to identify, report and help remediate security vulnerabilities. Watchfire has been the recipient of several industry honors including: winning an unprecedented three out of five 2007 SC Magazine Excellence Awards (including Best Security Company); the HP/IAPP Privacy Innovation Award, ; Computerworld's Innovative Technology Award; finalist for the pending Dr. Dobb's 2007 Jolt Product Excellence Awards; and "Recommended" rating by Computer Reseller News. For two years in a row, Watchfire has been named by IDC as the worldwide market share leader in web application vulnerability assessment software. Watchfire's partners include IBM Global Services, Fortify, PricewaterhouseCoopers, Sapient, Microsoft, Interwoven, EMC Documentum and Mercury. Watchfire is headquartered in Waltham, MA. For more information, please visit www.watchfire.com.

Related Links