+ Reply to Thread
Results 1 to 4 of 4

Thread: Security issue in Website Optimizer

  1. #1
    Administrator
    Join Date
    Jan 2010
    Location
    Essex, UK
    Posts
    7,279
    Blog Entries
    30
    Thanks
    3,904
    Thanked 2,643 Times in 1,497 Posts
    Rep Power
    101

    Security issue in Website Optimizer

    Google's website optimizer has a major flaw that allows a hacker to execute malicious script on your site.

    Anyone got the warning email from Google?
    Show your support - Like us on Facebook

  2. The Following User Says Thank You to Clinton For This Useful Post:

    Andy (December 7th, 2010)

  3. #2
    Senior Member
    Join Date
    Mar 2010
    Posts
    657
    Blog Entries
    53
    Thanks
    164
    Thanked 178 Times in 103 Posts
    Rep Power
    15
    Thanks Clinton. Never saw an email from G. It's good to know.

    Andy

    P.S. Just checked, I did get an email today.

  4. #3
    Top Contributor
    Join Date
    Feb 2010
    Location
    Nr Manchester UK
    Posts
    2,112
    Thanks
    287
    Thanked 643 Times in 372 Posts
    Rep Power
    35
    Yeah I got it too. I'm not terribly worried because "This attack can only take place if a website or browser has already been compromised by a separate attack" although I'd like to know what that other attack is.

    I like this proactive action though, emailing directly rather than just placing a warning in the GWO accounts or on their blog. If Google ever reach Microsoft's level of releasing 'vunerable' software I'll start to worry about them but this is the first time I've known this to happen, anyone know if it's ever happened before?.

  5. #4
    Administrator
    Join Date
    Jan 2010
    Location
    Essex, UK
    Posts
    7,279
    Blog Entries
    30
    Thanks
    3,904
    Thanked 2,643 Times in 1,497 Posts
    Rep Power
    101
    As SearchEngineLand reveals, there's been a second security alert from Google within 12 hours. This time it's the goo.gl URL shortening service (but that's more a Twitter problem).

    Google's blog doesn't seem to mention the scripting issue. Was the email sent out to only those with active experiments or to everyone?

    Anyone knows anything about the wider issue of cross site scripting attacks that this email raises which affects even those who don't have active experiments.
    Show your support - Like us on Facebook

+ Reply to Thread

Similar Threads

  1. WordPress Security Mod
    By tke71709 in forum Website 101
    Replies: 1
    Last Post: February 22nd, 2012, 8:20 AM
  2. Security problem
    By rogsmith in forum Website 101
    Replies: 12
    Last Post: January 20th, 2012, 8:25 AM
  3. Raising the issue of price with a seller
    By Clinton in forum Buying a Website, Blog, Internet Business
    Replies: 4
    Last Post: July 13th, 2010, 4:45 AM
  4. Security and Your Web Site
    By Andy in forum Website 101
    Replies: 3
    Last Post: April 30th, 2010, 10:51 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts