Python XSS flaw left Google open to attackers
A security researcher reveals how a scripting flaw left many Google services open to an attacker.

Google recently fixed a cross-site scripting vulnerability that could have allowed an attacker to take over a number of its services.
According to researcher Inferno' on Securethoughts.com, the vulnerability in Google's Support Python Script could have allowed an intruder to transfer a user's Google.com cookie to a malicious site.
This means that an attacker would have a user's Google.com domain cookie, which is the single sign-On cookie to all Google services.
A criminal could have had access to Google Mail, Contacts, Google Docs, Code, Sites, website analytics as well as be able to install malicious widgets in an iGoogle homepage.
However rather than publish the vulnerability, Inferno reported it straight to Google, which responded within the hour and fixed the flaw after a little more than two weeks.
Inferno said on the blog: "I believe in responsible disclosure, so I waited for this vulnerability to be fixed completely."
Inferno said that the time Google took to fix the flaw was due to vulnerable python script being used in lots of places.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
A Google spokesperson said: "We immediately investigated this issue after it was privately reported to us, and we resolved it prior to publication. We take the security of our users very seriously."
-
OpenAI just launched 'Codex', a new AI agent for software engineering
News OpenAI has unveiled the launch of a new AI agent, dubbed 'Codex', aimed specifically at supporting software engineering tasks.
-
Acer's new Swift Edge 14 AI is a MacBook Air killer
News Acer's new Swift Edge 14 AI is an ultra-lightweight, compact productivity powerhouse.
-
What is cross-site scripting (XSS)?
In-depth How XSS exploits work and how to defend against them
-
Hackers infiltrated analytics platform used by 2m sites to syphon Bitcoin from gate.io
News “Supply-chain attack” saw more than 680,000 sites actively infected but the code only specified an address used by gate.io
-
Vulnerabilities in web applications at the heart of 73% of breaches, Kaspersky finds
News Pen test analysis finds 43% of companies have low or extremely low levels of security
-
Researchers warn of nine vulnerabilities in Dell EMC's Isilon platform
News The company's OneFS storage OS is vulnerable to cross-site request forgeries and privilege escalation
-
Microsoft to fix IE XSS filter flaw in June
News Microsoft will fully patch the flaw in June, after it was disclosed at the European Black Hat conference.
-
Cross-scripting flaws patched in Adobe app software
News Adobe said that this time criminals haven’t had the time to take advantage of the vulnerabilities.