发新话题
打印

[转载]Attacks on Local Searching Tools

[转载]Attacks on Local Searching Tools

信息来源:邪恶八进制信息安全团队(www.eviloctal.com

The Google Desktop Search is an indexing tool, currently in beta testing, designed to allow users fast, intuitive, searching for local files. The principle interface is provided through a local web server which supports an interface similar to Google.com’s normal web page. Indexing of local files occurs when the system is idle, and understands a number of common file types. A optional feature is that Google Desktop can integrate a short summary of a local search results with Google.com web searches. This summary includes 30-40 character snippets of local files. In our research we searched for a vulnerability that would release private local data to an unauthorized remote entity. Our focus was on the small snippets of local data that the integration feature handled. We realized that this feature was combining local private data with remote public data in a possibly unsafe environment. We present two different attacks that exploit this vulnerability.

附件

Attacks on Local Searching Tools.rar (108 KB)

2005-10-4 21:53, 下载次数: 39

曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题