Global Security Watch > Phishing With Google Wave ha.ckers.org web application security lab
[ha.ckers.org web application security lab] The part that always bothers me is when they encourage webmasters to include Google code on other websites as though they are party favors. That’s in the first sentence of the Gadgets page, “Gadgets powered by Google are miniature objects made by Google users like you that offer cool and dynamic content that can be placed on any page on the web.”
[Previous] The Phishing Flow Chart Highlights Red Flags in Dangerous E...
[Next] Fraud Alerts and Identity Theft: is This Enough?...
Some related posts from Technorati and Google.
[Neowin.net] Neowin.net - Google Gadgets can be misused by phishers: Google Gadgets are little programs that gather information on the Web and then display them on multiple Web pages, making it easy for Webmasters to display everything from sports scores to astronomical data across their sites. The domain used to host small Google Gadget applications written by Web developers could be misused by phishers to get around antiphishing filters.
[What is google wave? | A Blog about Google Wave] Tech Week in Review 2-12-2010 - Black Web 2.0 » What is google ...: Contrary to popular belief, I don't think Wave was Google's big jump into social networking. Finally, taking a hint from …
[STEFBOY Nulled Scripts] Xploiting Google Gadgets: Gmalware and Beyond | STEFBOY Nulled Scripts: Phishing “Steal user passwords by faking login portals to webbased services, devices, or web sites.” Cross-Gadget Attacks Gadgets can attack one another, steal cookies and/or data, manipulate the content of other gadgets.
[Dy-Verse] Phishing with Google Wave: Phishing is usually be categorized under social engineering rather than a technical hack. It is inherently about tricking the user to click a link, or visit a web page.
[Geeky-Gadgets] Phishing Application Appears On Google Android Market: Droid09 launched this phishing attack from the Android Marketplace and its since been removed. Its called phishing because scammers go fishing for information about you or your financial account that may be used for identity theft.
[yang's blog] Making sense of OpenID, OAuth, OpenSocial, Google Friend Connect ...: the site you log in to to prove you really own that OpenID), but instead of sending you there (because, yes, OpenID works by having the site you’re logging in to send you to your provider) I send you to my fake provider, which then just proxies the real provider, stealing your login as it does. I don’t have to persuade you that I’m anything special, just someone who wants you to use OpenID, as the designers hope will become commonplace, and I don’t have to know your provider in advance.
[What is google wave? | A Blog about Google Wave] What Google Gets from Aardvark's Ask-A-Friend Service - PC World ...: In addition to the Buzz and Aardvark announcements, Google last year launched Google Wave, a somewhat nebulous communications and social app for the Web. …
[Gadget Helpline UK: Gadget Advice, Gadget help, Gadget manual, Gadget blog. The UK's number one gadget support club] Which Web Browser is Best? | Gadget Helpline UK: Gadget Advice ...: As well as being an open-source production, Chrome includes many different functions and features, all aimed to improve security, speed, and stability when browsing the web, such as periodically downloading a ”blacklist of sites that include phishing and malware, and displaying warnings before a user enters them.
[SoftSailor] Phishing Application, discovered in Android Market - SoftSailor: According to sources, all Android owners who installed apps created by developer Droid09, should be removed immediately, to avoid the risk of interception of data and to move on native web browsers being secure. The phishing app targeted the customers of First Tech Credit Union, who used it for different banking transactions.
[Technology: Technology blog | guardian.co.uk] How to confuse a Facebook user | Technology | guardian.co.uk: People are seeing the URL as a marker rather than a 'goer' as well. Although the interface of all browsers do use a standard input element for this (and afaik) have a blinking cursor in there when you open a new window - although perhaps not if the page is defaulting somewhere, and I think the root of the confusion lies in the fact that browsers often do have a default web site, so when you make a new window you are taken to Google say.
[Matt Cutts: Gadgets, Google, and SEO] Important blog post on Google blog: But after Google Emperor starts the war with China Government, I suddenly realise at the web time, the most powerful man is not American President, but Google Emperor because google Emperor’s war is invisible, google Emperor has billions of invisible soldiers everywhere in the world, google Emperor’s billions of invisible soldiers everywhere in the world do not take any salary from google”¦and google Emperor’s weapon is the web”¦more powerful than nuclear…so that I know google Emeperor will always win.
[IMvsMI blog] Xploiting Google Gadgets: Gmalware and Beyond: [...] more from the original source: Xploiting Google Gadgets: Gmalware and Beyond » IMvsMI blog Share and [...]
[ECP Writes] ECP Writes - I like Blogger best, as free blog-spots go: MySpace stopped allowing outgoing links to Blogger blogs, because of Blogger's bad reputation as a host for phishers, malware intallers and other splogger types. So far, I have not encountered restrictions on links to Blogspot URLs anywhere else.
Reflected tags on Technorati: Blog, Phishing, Global Security Watch