Google Plugs Hole That Lets You Remove Any Website
blowdart writes "Google today disabled their webmaster tools after it was discovered that anyone could use the tool to remove any site from the google index. The exploit was pretty simple, all anyone had to do was to have a google webmasters tool account and edit a query string parameter on a valid removal to point to a domain they didn't own!"
this hole was open long enough for someone to remove Expert Exchange & all the other BS...
/. was already removed from the internet. That's why no one is commenting.
Come to think of it, how did I get here? Where am I? I'm old.
Absolute power corrupts absolutely. indymedia
http://www.google.com/search?q=picard+facepalm&tbm=isch
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
http://bobby-tables.com/ Obligatory response.
http://www.supersecurewebsoftware.com/adminPages.aspx?admin=true&customeraccountaccess=true&warmfuzzyfeeling=true
Two of my imaginary friends reproduced once
That was fast. Someone mod parent informative.
Time to offend someone
Well, this is pretty bad, though I imagine it probably happened because one webmaster could control multiple domains that look dissimilar, and they forgot to add checks to make sure that the webmaster really controlled the requested one. Oops. Nowhere near as bad as this, which was simple gross, heads-should-roll, incompetence, but still a pretty big mistake. Kinda sad that address bar "hacks" still work in this day and age. Especially at a company like Google.
Looks like the removal isn't permanent, either, just temporary, so take that for what its worth. Still, wow, a malicious user could do serious damage to a lot of websites with this.
"None can love freedom heartily, but good men; the rest love not freedom, but license." --John Milton
What if someone used this exploit to remove Google.com? Then my parents couldn't enter 'google' in the white box (Google homepage) to get to 'the internet'!
Agh. I think my head exploded.
"I love animals! Some are cute, others are tasty, what's not to like?" - Betsy Schroeder, Jeopardy contestant
The author of this 'xploit' would have gotten more attention from Google if he tried removing 'google.com' and some other domains that belong to the company.
I think this is the closest one could get to breaking the Internet by 'typing google into google'.
You can't handle the truth.
The bug in webmaster tools has nothing to do with SQL injection, so although I like XKCD the two posts are quite irrelevant.
Stackoverflow still gives you better answers. I see no reason to even get their answers for free.
By the way, google should remove experts exchange, they give the googlebot the answer but try to hide from regular users.
Democracy Now! - your daily, uncensored, corporate-free
Lol. Excellent choice of comics you have there
.... This hole in Google's code doesn't affect the general availability of your site. It affects whether or not the site is contained in Google's index.
how is babby formed?
An awful lot of sites depend on visitors from search engines. No visitors = no business, so if you can block competing sites from the index (and thus from results), your business will be hurt badly.
They are both inserting unexpected data into an unverified field. The only difference is that with SQL injection you are inserting sql to do what you want instead of just data.
One wonders if Google can trace anyone who has previously used this technique to remove competitors from the index.
It would be fascinating to see just who has been a bad boy.
------ The best brain training is now totally free : )
With the security hole plugged, people who wish to remove their erroneous information online will need to use paid service such as Reputation Defender. I bet how much did RD paid to Google to get this fixed?
Twitter: @dainsanefh
The problem I see with deniable encryption is that while they can't prove there is more to see you can't prove that there isn't. So if they think the keys you have given them are decoys they will just keep tortuting you until you either reveal further keys or die.
note: i'm known as plugwash most places but i screwd up registering that here somehow in the past and now can't register
It's called Deniable Encryption
In the real world, deniable encryption means they beat you with the wrench even after you have given them a password that appears to work.
Ooops, I see. Probably an attempt to gain some traffic ...
Well, many attacks are based on unexpected values (if the developer expected that and it fails, he's a bit stupid). I was just pointing out this is not exactly SQL injection - the difference is that in this case there was a piece of business logic missing (check that the user is authorized to do that) and in case of SQL injection it's a failure at much lower level (data access).
Anyway, let's not argue about this and let's read some old XKCD strips we've already forgotten.
So then if somebody used this exploit to remove sites from Google, does that mean they'll mysteriously disappear from Bing?
=)
/* No Comment */