![]() |
Careful, exploit for google toolbar is out
A remote user can execute arbitrary scripting code in the Local Computer security zone.
It is reported that the 'About' section of the Google Toolbar does not properly filter HTML code. A remote user can create HTML that, when loaded by the target user, will invoke the About page and execute arbitrary scripting code in the context of the page. A demonstration exploit is provided: <s c r i p t> window.showModalDialog("res://C:\\Program%20Files\\Google\\GoogleToolbar1.dll/ABOUT.HTML", "<div style=\"background-image: url(javascript:alert(location.href));\">"); </s c r i p t> |
oh, shit
|
so should i bust a cap in my googlebar or what?
are they planning to offer an update/patch ala microsoft? |
very smart to post an example code
|
nothing happens
|
Use Firefox and if you want to see pageranks, install the extension below. Takes up a lot less space than google's toolbar.
Google Pagerank extension: http://www.tapouillo.com/firefox_extension/ |
|
Quote:
|
| All times are GMT -7. The time now is 12:59 PM. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123