Hacker News

hackinfo delivers the latest news updates related to Security breach, Cyber Crime, vulnerability, Cyber Security and Penetration testing tools and more.

  • Home
  • Beauty
  • Health
  • General
  • About

Recent Post

Total Pageviews

Blog Archive

  • ►  2015 (5)
    • ►  January (5)
  • ▼  2014 (41)
    • ►  December (10)
    • ►  November (1)
    • ►  October (9)
    • ►  September (3)
    • ▼  May (12)
      • Kali Linux website hacked by The GreaT Team
      • New variant of Java RAT can use your Android devic...
      • European Cyber Army leaks 60k credentials compromi...
      • RedHack claimed to have hacked ISP TTNET, Vodafone...
      • Phishing pages trick Steam users to Upload SSFN file
      • Report: Social Security numbers of Nearly 30,000 ...
      • BJP website blocked for Pakistan over repeated hac...
      • How researchers hack Google using XXE vulnerability !
      • Black Hat hacker Farid Essebar arrested in Thailand
      • Power Locker - Cybercriminals attempt to sell New ...
      • 17 year old suspected to be creator of BlackPOS ma...
      • Russian Hacker Rinat Shabayev admits to be creator...
    • ►  April (6)
Design by HunterDevil Copyright © 2014. Powered by Blogger.

Search This Blog

Pages

  • Home

Author

  • hi
  • hotnews.com

Infolinks in Text Ads

Hacker News

Followers

Home » Unlabelled » How researchers hack Google using XXE vulnerability !

Thursday, May 1, 2014

How researchers hack Google using XXE vulnerability !

Posted by hi Label :  No comments

Report: What is most secure website? NOTHING.  Even Google is vulnerable to all sort of attacks!

Security researchers and Co-Founders of  Detectify have discovered a critical security vulnerability in Google that allowed them to access Internal servers.

The vulnerability exists in the Google Toolbar button gallery.  The page allows users to customize their toolbar with buttons. It also allows users to create their own buttons by uploading XML file containing various meta data.

Researchers identified this function is vulnerable to XML External Entity vulnerability.

By sending a crafted XML file, researchers are able to gain access to internal files stored in one of Google's product server.  They have managed to read the 'etc/passwd' and 'etc/hosts' files of the server.

By exploiting this vulnerability, researchers could have accessed any files on the Google's server, also they could have done SSRF Exploitation to access internal systems.

Google has rewarded the researchers with $10,000 for finding and reporting this vulnerability.

Tweet
How researchers hack Google using XXE vulnerability ! Title : How researchers hack Google using XXE vulnerability !
Description : Report: What is most secure website? NOTHING.  Even Google is vulnerable to all sort of attacks! Security researchers and Co-Founders ...
Rating : 5

Popular Posts

  • popular Image board 4chan hacked
    The next day after Bihar BJP's official website get hacked by hacker claimed to be from Pakistan, the official website of Senior B...
  • NASA and the ESA confirm that the lost Beagle-2 orbiter has been found on Mars
    Back in 2003, a full month before NASA’s Opportunity landed on Mars, the British probe Beagle-2 entered orbit as part of the Mars Expres...
  • NASA’s New Horizons space probe: Powered by PlayStation
    Today is a milestone for the New Horizons probe. The spacecraft, which launched nearly nine years ago, has just begun its official six...
  • NVIDIA DEMOS A CAR COMPUTER TRAINED WITH “DEEP LEARNING”
    Many cars now include cameras or other sensors that record the passing world and trigger intelligent behavior, such as automatic braking o...
  • Chemical-Sensing Displays and Other Surprising Uses of Glass
    An inside look at Corning’s labs suggests what’s next for the inventor of Gorilla Glass. Someday your smartphone might be able to help...
  • Toyota Recalls 20,000 Vehicles For Possible Fuel Leak
    Chevy Motor Corp said it’s remembering about 20,000 automobiles globally over possible energy leaking, Reuters revealed on Friday. Most o...
  • Desalination out of Desperation
    Even in drought-stricken California, San Diego stands out. It gets less rain than parched Los Angeles or Fresno. The region has less groundw...
  • South Korea nuclear plant hit by hacker
    The hacking comes in the wake of increased tension and trouble from North Korea, though the source has not been confirmed. Computers a...
  • News Details of 5 of the best hackers in the world
    There are many hackers around the world. Hackers are famous for their many, many infamous and distinguished or None. Today's top 5 in...
  • INTEL’S BROADWELL IS COMING TO MAINSTREAM LAPTOPS
    Intel’s Broadwell is coming to mainstream laptops — here’s what you need to know CES has always been a major launch window for Intel a...

 
Hacker News © 2014. All Right Reserved
DMCA | Privacy Policy
  • Facebook
  • twitter
  • googleplus
  • youtube