Google XXE

Google External Entity vulnerability to Google gives access to host servers

Ανακαλύφθηκε μια κρίσιμη on Google ( XML External ή XXE ) που θα μπορούσε να επιτρέψει σε έναν εισβολέα να αποκτήσει πρόσβαση σε εσωτερικά αρχεία των servers της εταιρείας. Ακούγεται σαν ανέκδοτο, αλλά η ευπάθεια ανακαλύφθηκε πραγματικά από τους ερευνητές ασφαλείας της Detectify.

XML External Entity

The vulnerability was in Button Gallery. The team of researchers discovered a void when he noticed that Google Toolbar Gallery Button allows them να προσαρμόσουν στις γραμμές εργαλείων τους νέα κουμπιά. Έτσι, για τους προγραμματιστές, ήταν εύκολο να δημιουργήσουν δικά τους κουμπιά και να ανεβάσουν τα XML αρχεία με μεταδεδομένα styling και άλλες τέτοια .

But as it turned out, this Google service was vulnerable to XML External Entity (XXE). The XML External Entity is an XML injection that allows an attacker to force the installation of malicious XML that can compromise the security of a web application.

The researchers created their own button containing malicious XML code, which I aimed to "fish" data from Google's servers. Uploading this file, they were able to access internal files stored on one of Google's production servers and successfully read the files

By exploiting the same vulnerability as reported by the researchers they could have access to any other file on the company's server, or could gain access to their internal systems through the use of SSRF.

Researchers reported vulnerability to the Google security team and were rewarded with 10.000 dollars from the company.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).