Showing posts with label Google Account. Show all posts
Showing posts with label Google Account. Show all posts

Friday, 13 February 2015

Google Rewards Users For Security Check With 2GB Storage


As part of Safer Internet Day gives Google users Google Drive 2 gigabytes of additional storage when a security check to perform. According to the Internet giant, users can check their account this way or it is secured. It prompts you to verify the data with which an account can be restored.


In case Google suspicious activity in an account detects users are accessed through this data. The second step in the security check consists of verifying the credentials. This allows users to see if there are others with stolen credentials to login to their account. Finally, it should be confirmed that apps and devices allowed to access account information. Once the audit is performed, there will be at the end of this month 2GB of storage space to be added. The action of Google is 17th February.

Thursday, 12 February 2015

Google Play Leak Makes Possible Automatic Install Apps


A vulnerability in the Google Play Store allows attackers to install apps from automatically from the store on the devices of Android users. The problem is caused by the Google Play support domain no X-Frame-Options (XFO).

A malicious user could then through Cross-Site Scripting (XSS) in a particular part of the Google Play web application, or via Universal XSS (UXSS) remotely install any app from Google Play and start. According to Todd Beardsley security company Rapid7 are many versions of Android 4.3 (Jelly Bean) and previously supplied with browsers that are vulnerable to UXSS.

In addition, there is the possibility that users themselves have installed a vulnerable browsers. Users who want to protect themselves against the problem have therefore advised to use a browser which does not occur frequently UXSS vulnerabilities, such as Google Chrome, Mozilla Firefox or Dolphin Browser. Another solution is not to be logged into a Google account while surfing.

The problem was reported to Google on December 12 last year. However, no mention is made of the vulnerability is fixed.Rapid7 did create a module for Metasploit to demonstrate the vulnerability. Metasploit is a framework for testing the safety of the systems. The now published module combines two vulnerabilities to execute arbitrary code on Android Devices.

First create the module using a UXSS leak in the default Android browser, as well as various other browsers on Android 4.3 and above. In addition, maintains the Google Play web interface no X-Frame-Options and is therefore vulnerable to script injection. The end result is the remote execution of code from Google Play's feature to remotely install apps. An attacker can therefore install and start anywhere in the Play store.