<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Google Docs puts Google Users at Risk</title>
	<atom:link href="http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/feed/" rel="self" type="application/rss+xml" />
	<link>http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-docs-puts-google-users-at-risk</link>
	<description>Thoughts on Security in an Uncivilized World…</description>
	<lastBuildDate>Fri, 27 Apr 2012 13:53:43 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Google Health &#171; NonaTheNinja</title>
		<link>http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/comment-page-1/#comment-487</link>
		<dc:creator>Google Health &#171; NonaTheNinja</dc:creator>
		<pubDate>Fri, 23 May 2008 14:02:18 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/#comment-487</guid>
		<description>[...] commented on the article, mentioning several past vulnerabilities: ownership of content issues, Google Docs theft, a cross-domain hole, Google XSS, and a Google Picasa protocol handler issue leading to [...]</description>
		<content:encoded><![CDATA[<p>[...] commented on the article, mentioning several past vulnerabilities: ownership of content issues, Google Docs theft, a cross-domain hole, Google XSS, and a Google Picasa protocol handler issue leading to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Google Health dissed by RSnake &#124; My Blog Posts</title>
		<link>http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/comment-page-1/#comment-486</link>
		<dc:creator>Google Health dissed by RSnake &#124; My Blog Posts</dc:creator>
		<pubDate>Fri, 23 May 2008 12:49:09 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/#comment-486</guid>
		<description>[...] commented on the article, mentioning several past vulnerabilities: ownership of content issues, Google Docs theft, a cross-domain hole, Google XSS, and a Google Picasa protocol handler issue leading to [...]</description>
		<content:encoded><![CDATA[<p>[...] commented on the article, mentioning several past vulnerabilities: ownership of content issues, Google Docs theft, a cross-domain hole, Google XSS, and a Google Picasa protocol handler issue leading to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero Day mobile edition</title>
		<link>http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/comment-page-1/#comment-484</link>
		<dc:creator>Zero Day mobile edition</dc:creator>
		<pubDate>Thu, 22 May 2008 18:41:14 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/#comment-484</guid>
		<description>[...] of the more interesting attacks pulled off on Google applications, see Billy Rios and my previous work on Google Docs, get&#8217;s only as much coverage as the security researcher who did or did not disclose the [...]</description>
		<content:encoded><![CDATA[<p>[...] of the more interesting attacks pulled off on Google applications, see Billy Rios and my previous work on Google Docs, get&#8217;s only as much coverage as the security researcher who did or did not disclose the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Telamoon</title>
		<link>http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/comment-page-1/#comment-186</link>
		<dc:creator>Telamoon</dc:creator>
		<pubDate>Fri, 28 Sep 2007 19:49:07 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/#comment-186</guid>
		<description>Nice post xssniper. Quite an eyeopener. I&#039;m a firm believer in the SAAS model and I&#039;ve just started using Googledocs at our company. I&#039;ll be folowing this with special interest.  Anyone know if these issues also known to effect the MS Office Live env or does MS do it different?</description>
		<content:encoded><![CDATA[<p>Nice post xssniper. Quite an eyeopener. I&#8217;m a firm believer in the SAAS model and I&#8217;ve just started using Googledocs at our company. I&#8217;ll be folowing this with special interest.  Anyone know if these issues also known to effect the MS Office Live env or does MS do it different?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xssniper</title>
		<link>http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/comment-page-1/#comment-177</link>
		<dc:creator>xssniper</dc:creator>
		<pubDate>Wed, 26 Sep 2007 16:16:49 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/#comment-177</guid>
		<description>@Rosario - Ahhh... if only it were so easy.  Causing the browser to display sensitive content and pulling that sensitive content to an attacker controlled domain are two totally different things my friend.

The second item is left as an exercise for the reader,but all the heavy lifting is already done for you...</description>
		<content:encoded><![CDATA[<p>@Rosario &#8211; Ahhh&#8230; if only it were so easy.  Causing the browser to display sensitive content and pulling that sensitive content to an attacker controlled domain are two totally different things my friend.</p>
<p>The second item is left as an exercise for the reader,but all the heavy lifting is already done for you&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rosario Valotta</title>
		<link>http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/comment-page-1/#comment-176</link>
		<dc:creator>Rosario Valotta</dc:creator>
		<pubDate>Wed, 26 Sep 2007 15:47:31 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/#comment-176</guid>
		<description>Sad September for Google Security team...
Looking at your PoC I&#039;ve noticed that a more simple CSRF can be used to steal contacts as the remote resourse is not token-protected:
http://docs.google.com/contacts/data/contacts?thumb=true&amp;groups=true&amp;show=ALL&amp;enums=true&amp;psort=Name&amp;max=900
(e.g using  )
More, Adobe livedoc states that loading the crossdomain file from docs.google.com your application can access &quot;only&quot; to that domain...how can you access resource from mail.google.com domain? Is it the missing step? :-)</description>
		<content:encoded><![CDATA[<p>Sad September for Google Security team&#8230;<br />
Looking at your PoC I&#8217;ve noticed that a more simple CSRF can be used to steal contacts as the remote resourse is not token-protected:<br />
<a href="http://docs.google.com/contacts/data/contacts?thumb=true&#038;groups=true&#038;show=ALL&#038;enums=true&#038;psort=Name&#038;max=900" rel="nofollow">http://docs.google.com/contacts/data/contacts?thumb=true&#038;groups=true&#038;show=ALL&#038;enums=true&#038;psort=Name&#038;max=900</a><br />
(e.g using  )<br />
More, Adobe livedoc states that loading the crossdomain file from docs.google.com your application can access &#8220;only&#8221; to that domain&#8230;how can you access resource from mail.google.com domain? Is it the missing step? <img src='http://xs-sniper.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan McFeters</title>
		<link>http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/comment-page-1/#comment-174</link>
		<dc:creator>Nathan McFeters</dc:creator>
		<pubDate>Wed, 26 Sep 2007 14:41:20 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/#comment-174</guid>
		<description>The day that the implement crossdomain.xml in JavaScript will be a very very sad day... at least right now I can install a browser that doesn&#039;t support flash... I mean, the whole web requires JS.</description>
		<content:encoded><![CDATA[<p>The day that the implement crossdomain.xml in JavaScript will be a very very sad day&#8230; at least right now I can install a browser that doesn&#8217;t support flash&#8230; I mean, the whole web requires JS.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xssniper</title>
		<link>http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/comment-page-1/#comment-173</link>
		<dc:creator>xssniper</dc:creator>
		<pubDate>Wed, 26 Sep 2007 14:40:16 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/#comment-173</guid>
		<description>@MartinJ - Still works for me at this time.  I haven&#039;t tested it with Safari, but it should still work as I&#039;m obeying all of Flash&#039;s cross domain rules.  It seems that pulling cross domain content with a Flash Object loaded by Firefox is a little buggy.  Some instances of Firefox require  a refresh in order for the list to appear (which I built into the page).  Is the page refreshing after 10 seconds in your browser?

BK</description>
		<content:encoded><![CDATA[<p>@MartinJ &#8211; Still works for me at this time.  I haven&#8217;t tested it with Safari, but it should still work as I&#8217;m obeying all of Flash&#8217;s cross domain rules.  It seems that pulling cross domain content with a Flash Object loaded by Firefox is a little buggy.  Some instances of Firefox require  a refresh in order for the list to appear (which I built into the page).  Is the page refreshing after 10 seconds in your browser?</p>
<p>BK</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MartinJ</title>
		<link>http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/comment-page-1/#comment-171</link>
		<dc:creator>MartinJ</dc:creator>
		<pubDate>Wed, 26 Sep 2007 12:31:53 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/#comment-171</guid>
		<description>Has this been fixed? The PoC does not work for me (tested on Firefox and Safari)</description>
		<content:encoded><![CDATA[<p>Has this been fixed? The PoC does not work for me (tested on Firefox and Safari)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .mario</title>
		<link>http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/comment-page-1/#comment-170</link>
		<dc:creator>.mario</dc:creator>
		<pubDate>Wed, 26 Sep 2007 12:06:46 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/26/google-docs-puts-google-users-at-risk/#comment-170</guid>
		<description>&quot;On another note, the W3C people are thinking of implementing the crossdomain.xml concept for browser JS as well. To me, this is just plain bad idea!!!&quot;

Sweet Jesus - nooo... I didn&#039;t know that but dreamt about it.

Nice find Billy AND/OR Nate!</description>
		<content:encoded><![CDATA[<p>&#8220;On another note, the W3C people are thinking of implementing the crossdomain.xml concept for browser JS as well. To me, this is just plain bad idea!!!&#8221;</p>
<p>Sweet Jesus &#8211; nooo&#8230; I didn&#8217;t know that but dreamt about it.</p>
<p>Nice find Billy AND/OR Nate!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced

Served from: xs-sniper.com @ 2012-05-16 22:01:21 -->
