12 ms·
XSS in Google Finance
- eli 13y agoNice one. Curious how it was discovered. Manually toying with URL parameters on google.com links?
- xSwag 13y agoAutomatic analysis would have to be amazing to detect something like this. I'm assuming this was found manually. I wonder how long it took.
- orf 13y agoIt really wouldn't, URL's like this in parameters are a huge red flag for both humans and automated tools. Any half decent analyzer would just need to see that parameter in any page it scraped.
- DouweM 13y agoI'm not familiar with Google Finance, but the author states "This part of the code is responsible for querying an external domain for a newsfeed to be displayed on the plot as an overlay.". I'm guessing they just happened to come across a Google Finance URL using the &ntrssurl= parameter and figured that would be worth digging into.
- Ecio78 13y agoHe says also in the comments: "Manual testing, the ntrssurl parameter was present in an example in the documentation for adding custom news feeds to the plot :) ."
- skizm 13y agoSlightly off topic, but if a bug like this is discovered does the engineer who wrote it get notified? It would be funny to have a sort of wall of shame for that week or something else internally. Or you could even go as far as making that engineer pay for the bug bounty (that's a bit much though). Anyone have any experience as to what happens on Google's end besides the obviously patching of the bug and paying of the fine?
- eieio 13y agoIt might be funny but I can't imagine that shaming engineers like that would be very productive. Anyone talented enough to be working at a place like Google is likely going to be plenty embarrassed without a "wall of shame" to make sure everyone knows who screwed up. Not a Google employee but I'd imagine they'd have to do some kind of writeup about what happened/how future errors like this will be prevented.
- Afforess 13y agoA wall of shame sounds amusing at first blush, but it would quickly become a source of a lot of negativity and unhappiness. Yes, developers need to be aware of bugs, and learn from mistakes, but intentional harassment seems a step too far. I know I've written thousands of bugs.
- skizm 13y agoI agree it can definitely turn counter-productive quickly. On the other hand, if not a wall of shame, I would like to know what happened if it was my code.
- ketralnis 13y agoA friend that used to work at Apple once told me a story of their department having a big banner over the desk of the last person to broke the build. Eventually a frustrated recipient of the banner solved the problems causing it to be brittle in the first place, and as a result had the banner himself for months. A rather unexpected disincentive to solve the problem
- astral303 13y agoI hope that the engineer(s) that wrote it get notified, so that they get the feedback on their decisions. If I write code with bugs that make it to production, I'd sure would like to know, even if I'm not the one fixing it. (This is the major reason why I think having sustaining/continuing engineering departments in software companies is a bad idea).
- ChuckMcM 13y agoActually there was (probably still is) an internal newsletter from the security team on the latest stuff that anyone who does anything customer facing should read. I really enjoyed reading it, both the writing was creative (engaging as opposed to obfuscating :-) and the topics sort of like logic puzzles.
- h1fra 13y ago5k is not so much for this kind of huge vulnerability. I mean with a "great" hack this guy could have made much more in a few hour, but let say it's a generous reward anyway :)
- seldo 13y agoDoes anyone else feel that XSS on google.com is probably worth a bit more to the wrong people than $5k? Arbitrary-eval is pretty much the worst. Unless I'm missing something, somebody could steal a user's cookie strings and post them to an arbitrary endpoint, which could then use them to log into, e.g. GMail, which an attacker could then use to trigger and retrieve password-reset links for all sorts of other sites. When I worked at Yahoo, an XSS on yahoo.com (which almost never happened) was a code-red, drop-everything, holy-shit event. If I were at Google I'd probably give this guy a bonus.
- RKearney 13y agoIn addition to the session ID cookies, you need the HSID cookie as well, which is HttpOnly. While this type of bug is bad, it doesn't allow for a malicious third party to get all of the cookies needed to take over the users session.
- arkem 13y agoAlso compartmentalization helps (Keeping products in different javascript origins, e.g. mail.google.com, accounts.google.com, etc)
- seldo 13y agoYes, but Google Finance is on google.com/finance (for some reason; I'm sure it used to be finance.google.com at some point...). The importance of httpOnly had somehow escaped me until today :-)
- hkmurakami 13y agoI use Google Finance, Yahoo Finance, Marketwatch, Bloomberg and the WSJ stock pages very frequently and can confirm that Google Finance was on finance.google.com until quite recently. Pretty sure it was there earlier this year.
- PavlovsCat 13y agoYes, but Google Finance is on google.com/finance (for some reason; I'm sure it used to be finance.google.com at some point...). Cookies set for just subdomain.hostname.com can only be "seen by" that particular subdomain, while cookies set for hostname.com can be seen from hostname.com and any and all subdomains. I think that's why they do it constantly, at least stuff like www.google.com/glass certainly makes no sense otherwise. Why not make a fancy new domain for that? I think it's cookie greed.
- jayzalowitz 13y agoWasn't this one around for ages?
- sneak 13y agoI wonder if emailing them and asking for e.g. a 25k reward before disclosure exposes one to criminal liability or not. I mean, is there a law making it illegal to sell exploits to the black market? These bug bounty programs must know they compete with a large market for these sorts of things.
- pestaa 13y agoIANAL, but action with malicious intent is pretty much enough to get you behind bars.
- sneak 13y agoNot always. For example, speaking truthful factual statements with malicious intent to harm someone's business by damaging their reputation is totally legal, provided you're not defrauding or blackmailing anyone or otherwise acting sketchy. There're a lot of actions based on malicious intent that are (and should remain) legal.
- jrockway 13y agoI think the goal of the $5000 is not to discourage criminals, but rather to encourage someone who notices an issue to write it up, produce a test case, bother to send an email to security@, and then follow up rather than just say "LOL, idiots" and move on with their life. The $5000 is also a nice incentive to keep looking around.
- tantalor 13y agoIf you sell me the exploit, and I use it to perform a crime, then I believe you may also be charged as an accessory. IANAL.
- gaborcselle 13y agoWhere in the code is the eval() is performed? There is not a single call to eval() in that source. Maybe a listing of the Wi() function would be useful.