Showing posts with label Google Password Alert. Show all posts
Showing posts with label Google Password Alert. Show all posts

Monday, 4 May 2015

Cat-And-Mouse Game Around Google Password Alert Continues



There is now a real cat-and-mouse game developed around the Password Alert extension from Google that should protect Chrome users from phishing attacks, but has become an attractive target of investigators still trying to bypass the expansion and there also manage.

Password Alert allows users to enter their Google password on a phishing site get a warning. It is then possible to change the password from the warning. Earlier this week succeeded the British security consultant Paul Moore managed to evade Password Alert via a script of seven lines. Users were given in this case, no warning when their Google password on a phishing site filled in.

Google launched an update to version 1.4, which was also by Moore circumvented . Again, Google published a new version, 1.5, which the Dutch security company Securify came up with a way to bypass the warning. It did not take long before Google had this attack captured and released version 1.6. Researchers have now also passed this version, which is the latest version, to circumvent .

"Today, we have again found a new way to bypass Password Alert. By the login form to load an iframe which Javascript is disabled, it is no longer possible for Password Alert to capture keystrokes. This detection does not work anymore" says Yorick Koster of Securify. "In fact, this is a cat-and-mouse game, the extension checks if a user Google account information entered:. Email address and password When one of the two no longer good comes through, then the detection is not working.."

Saturday, 2 May 2015

Google Password Alert Patched And Again Circumvented



Wednesday, Google unveiled an extension for Chrome that Google password to protect the users against phishing attacks. Once users to a phishing site have completed their password they get a warning Password Alert , as the extension is called, and the ability to change their Google password.


The operation was not infallible, because not a day later, the British security consultant Paul Moore Password Alert via a script of seven lines circumvented , as he made ​​via Twitter announced. The script, which the consultant claimed it made ​​in two minutes, ensured that users were given no warning to be seen. Today Google launched an update to version 1.4 to address the onslaught of Moore. An hour ago, Moore, however, managed to also get around this version, let him again via Twitter know.

Update May 2

The Dutch security company Securify published yesterday a comprehensive proof-of-concept in order to avoid the extension, but it seems that Google has solved this attack since yesterday version 1.5 appeared.