Get a Pentest and security assessment of your IT network.

Cyber Security

Researchers Get $10,000 for Hacking Google Server with Malicious XML

A critical vulnerability has been uncovered in Google that could allow an attacker to access the internal files of Google’s production servers. The vulnerability resides in the Toolbar Button Gallery, which allows users to customize their toolbars with new buttons. The researchers crafted their own button containing fishy XML entities. By sending it, they gain access to internal files stored in Google’s servers and managed to read the “/etc/passwd” and the /etc/hosts” files from the server. By exploiting the same vulnerability the researchers said they could have access any other file on their server, or could have gained access to their internal systems.

Source: https://thehackernews.com/2014/04/hacking-google-server-XML-External-Entity.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security