<![CDATA[Latest posts for the topic "Google Wap Proxy Vulnerability - BKIS"]]> /hvaonline/posts/list/13.html JForum - http://www.jforum.net Google Wap Proxy Vulnerability - BKIS http://packetstormsecurity.org/0812-exploits/SVRT-08-08.txt [SVRT-08-08] Google Wap Proxy Vulnerability can be exploited by Hackers to attack Internet Users 1. General Information On 15 December 2008, SVRT-BKIS, from BKIS Center, has found a vulnerability in the Wap Proxy service of Google, which allows hackers to cheat Internet users. With this flaw, users are to think that they are using a trustworthy service supplied by Google while all their actions are actually performed on websites prepared by hackers. This means hackers can easily steal users' sensitive information. We have been warning of this hole to Google. Details : http://security.bkis.vn/?p=310 SVRT Advisory : SVRT-08-08 Initial vendor notification : 12-16-2008 Release Date : 12-27-2008 Update Date : 12-27-2008 Discovered by : Dau Huy Ngoc - SVRT-Bkis Security Rating : Critical Impact : Phishing Affected Software http://google.com/gwt/n ; http://wap.google.com/gwt/n Proof of concept: http://google.com/gwt/n?u=http://security.bkis.vn/Proof-of-concept/Google/GmailWap.htm Video Demonstration : You can download at http://security.bkis.vn/Proof-of-concept/Google/GoogleWapProxyVuln.wmv or view at http://www.youtube.com/watch?v=h654Cj-uRQY 2. Technical Description Google Wap Proxy, also known as Google Wireless Transcoder, is a service that helps translate the content of an arbitrary website into XHTML format suitable for Wap browsers on cell phones. Making use of this service, when users access the link http://google.com/gwt/n?u=[http://website] with their cell phones, the content displayed by the browsers will be translated from that of the website at [http://website]. However, if [http://website] is the address of a website prepared by a hacker, he/she can definitely take advantage of the service to deceive users. In order to perform the attack, a hacker creates a website with the interface similar to that of Google. Then he's/she's in some way sending users a link in the form http://google.com/gwt/n?u=[http://fake-google-website]. As this link starts with google.com or wap.google.com, domain of Google, users might think it is safe and follow all the operations arranged by hackers, which results in their losing sensitive information. In fact, if this service only translated and displayed contents of websites, there would be no flaw to be exploited by hackers. The Achilles' heel is that users can interact with the websites, in other words, they can still login, input personal information and credit card information. via Wap Proxy. If the website in effect is created by hackers, all users' actions will be saved on hackers' servers. And for this reason, the vulnerability is due to a design fault in Google Wap Proxy Service. We have tested it with a fake website that has the interface identical to the Gmail login page. When users login via the site, their accounts and passwords will be disclosed. Follow this link to check for the test: http://google.com/gwt/n?u=http://security.bkis.vn/Proof-of-concept/Google/GmailWap.htm This service supports cell phone users but due to the fact that the provided links could be both wap.google.com and google.com, it also affects all Internet users in general. 3. Solution Rating this vulnerability high severity, Bkis Center recommends that users: - Only log into their Gmail accounts at the address www.google.com/accounts. - Do not perform actions such as logging in, inputting sensitive information. when using Google Wap Proxy service. - Be cautious with strange links, even links starting with domain names of well-known organizations like Google, Yahoo!, and Microsoft. Credits Thanks to Dau Huy Ngoc for working together with us in the detection and alert process of this vulnerability. SVRT-Bkis]]> /hvaonline/posts/list/27043.html#164775 /hvaonline/posts/list/27043.html#164775 GMT Re: Google Wap Proxy Vulnerability - BKIS Rating this vulnerability high severity, Bkis Center recommends that users: Security Rating Critical   Cái chức năng vốn dĩ của nó là... translate cái website thành WAP. Mà giờ đòi nó không translate thì... vứt đi cho rồi. Còn fake login là do user thôi, không phải lỗi của Google. CRITICAL, kinh thật ;-) Tui mới phát hiện ra 1 lỗi CRITICAL nữa nè, chắc sắp được Google thank you roài :-O : http://google.com/translate_c?hl=en&sl=vi&tl=en&u=http://security.bkis.vn/Proof-of-concept/Google/GmailWap.htm&usg=ALkJrhixq8zDm6DCli53lT7neoWbP9k15A PS: Lưu ý nha, đường link từ Google đó. Site giả mạo đó nha, đừng enter password -:-)
Solution Rating this vulnerability high severity, Bkis Center recommends that users: - Only log into their Gmail accounts at the address www.google.com/accounts. - Do not perform actions such as logging in, inputting sensitive information… when using Google Wap Proxy service. - Be cautious with strange links, even links starting with domain names of well-known organizations like Google, Yahoo!, and Microsoft… - Don't use Google Wap Proxy and Google Translate (Cái này do tui tự thêm vào :P)  
BKIS công bố mấy cái "lỗi"... nhảm quá. Từ xác định mặt người qua hình chụp tới cái vụ này. Nếu nghiên cứu về bảo mật thì nên công bố những bugs đàng hoàng 1 tí. Cùng IT với nhau cả, nói sự thật, có thể mất lòng, nhưng không có ý mỉa mai. Mong BKIS nghiêm túc hơn.]]>
/hvaonline/posts/list/27043.html#164779 /hvaonline/posts/list/27043.html#164779 GMT
Re: Google Wap Proxy Vulnerability - BKIS

BKIS wrote:
3. Solution Rating this vulnerability high severity, Bkis Center recommends that users: - Only log into their Gmail accounts at the address www.google.com/accounts. - Do not perform actions such as logging in, inputting sensitiveinformation. when using Google Wap Proxy service. - Be cautious with strange links, even links starting with domain names of well-known organizations like Google, Yahoo!, and Microsoft.  
Quan niệm của tôi, lỗ hổng không nhất thiết lúc nào cũng phải là Buffer Overflow, SQL Injection, XSS... Ý kiến của mọi người thì thế nào ? Nhưng nếu chúng ta chỉ coi đó mới là lỗi "đàng hoàng 1 tí", thì tôi cũng thấy BKIS đã từng phát hiện và cảnh báo các lỗi như thế. Tôi không nhớ hết khi đọc blog của họ, nhưng cũng thấy: Wireshark, MVNForum, K-Lite, Google Chrome .... Trên đây là một chút quan điểm cá nhân, không khen BKIS, cũng như không chê họ. Tôi viết ra cảm nhận của mình. ]]>
/hvaonline/posts/list/27043.html#164821 /hvaonline/posts/list/27043.html#164821 GMT
Re: Google Wap Proxy Vulnerability - BKIS /hvaonline/posts/list/27043.html#164824 /hvaonline/posts/list/27043.html#164824 GMT Re: Google Wap Proxy Vulnerability - BKIS We have been warning of this hole to Google.   Không biết bên Google trả lời lại chưa và trả lời như thế nào? :) ]]> /hvaonline/posts/list/27043.html#164826 /hvaonline/posts/list/27043.html#164826 GMT Re: Google Wap Proxy Vulnerability - BKIS critical", và càng không phải là 1 bug. Bug này (nếu có xảy ra), thì là do người dùng bất cẩn click vào link (phishing - lỗi của người dùng) chứ không phải xảy ra bởi Google.]]> /hvaonline/posts/list/27043.html#164829 /hvaonline/posts/list/27043.html#164829 GMT Re: Google Wap Proxy Vulnerability - BKIS /hvaonline/posts/list/27043.html#164830 /hvaonline/posts/list/27043.html#164830 GMT Re: Google Wap Proxy Vulnerability - BKIS

gamma95 wrote:
Cái này xếp vào loại Tips / Tricks thôi, ko thể gán nó vào mức là critical để to mồm :D  
Đối với anh em ta thì chỉ là Tip/Trick/Warning ... nhưng đối với BKIS thì nó là critical mà :D "Quay đầu là bờ", thế mà mấy chú bên BKIS không chịu thấy bờ bến gì.]]>
/hvaonline/posts/list/27043.html#165384 /hvaonline/posts/list/27043.html#165384 GMT