Slashdot Mirror


Google Public Service Search Makes for Easy Phishing

lisah writes "According to reports at NewsForge this morning, Developer Eric Farraro has discovered a potential hole in Google's Public Search Service that may leave the door wide open for phishing scams. The Public Search Service, designed to allow universities and other non-profit institutions to add Google search capabilities to their websites, provides code that allows website developers to customize the header and footer of the search results page. Handy (and malicious) coders can manipulate the headers and footers to create what looks like a Google sign-in page and then collect the login names and passwords of unsuspecting users." NewsForge and Slashdot are both owned by OSTG.

5 of 40 comments (clear)

  1. Re:Not a google issue... by dontbflat · · Score: 5, Insightful

    Its google's issue because they are HOSTING it. If they werent hosting the code, then fine. But they are and thats where the problem lies.

  2. Re:Not a google issue... by Infinityis · · Score: 4, Insightful

    The problem is that usually people can type in the URL from a suspicious looking email and prevent phishing attacks. In this case, typing in the URL took to you precisely the same site. All the anti-phishing advice you've been giving your family and friends would prove useless under these circumstances.

  3. Ackbar'ed by Infinityis · · Score: 4, Funny

    IT'S A TRAP

  4. Screw up of Google by mapkinase · · Score: 4, Insightful

    This is very Google-specific screw-up. It is not like they forgot to change some default setting, it is a specifically designed feature that went wrong.

    Google certainly does not do evil, but it is not exactly catching in the rye.

    --
    I do not believe in karma. "Funny"=-6. Do good and forbid evil. Yours, Oft-Offtopic Flamebaiting Troll.
  5. Re:Give a man a fish... by AugustZephyr · · Score: 4, Funny

    On a simliar note....
    Build a man a fire and keep him warm for a night. Set a man on fire and you will keep him warm for the rest of his life.