Google won't fix login page flaw that can lead to malware download

Google has said it will not fix a potential security flaw that could trick a user into downloading malware from its login window.

The company told security researcher Aidan Woods it "made the decision not to track" his bug bounty submission as a vulnerability.

Woods explained on his blog that Google's login screen allows an app or service to redirect to a page after the user signs in.

The theory goes that an attacker could trick a user into clicking a link that points to a malware file.

But Google said that the redirect page has to fall within "*google.com" domains, limiting its impact.

The problem, said Woods, is that malware hosted on "drive.google.com" or "docs.google.com" which fall within the Google subdomain parameters could still be used to serve up malware, and hide it as a genuine Google login page.

The search giant said in its reply to Woods: "Only first reports of technical security vulnerabilities that substantially affect the confidentiality or integrity of our users' data are in scope, and we feel the issue you mentioned does not meet that bar."

Woods, believing Google didn't fully understand the issue, published the full exchange of emails on his blog.


Source: Google won't fix login page flaw that can lead to malware download | ZDNet

See also: Aidan Woods - Google's Faulty Login Pages
 
I suppose that for the time being that users should use another page to log in or better yet not click on suspicious links.
 

My Computers

System One System Two

  • Operating System
    Windows 8.1 Industry Pro x64
    Manufacturer/Model
    HP Pavillion Elite HPE-250f
    CPU
    Intel i7 860 Quad core 2.8 ghz
    Memory
    8 gb
    Graphics Card(s)
    ATI Radeon HD 5770 1 gb ram
    Monitor(s) Displays
    Alienware 25 AW2521HF
    Screen Resolution
    1920x1080 &1680x1050
    Hard Drives
    1 TB x2
    Other Info
    https://www.cnet.com/products/hp-pavilion-elite-hpe-250f/
  • Operating System
    Windows 2012 R2 Data center/Linux Mint
    Manufacturer/Model
    Dell Poweredge T140
    CPU
    i3 9100 3.6GHz, 8M cache, 4C/4T
    Memory
    8GB 2666MT/s DDR4 ECC UDIMM
    Screen Resolution
    1680x1050
    Hard Drives
    1 TB & 360 GB x2
    Other Info
    https://www.dell.com/en-us/work/shop/productdetailstxn/poweredge-t140?~ck=bt
Back
Top