ie8 fix
Click Here

Googling Google

Christopher Dawson

Google Page Creator security flaw?

By | March 6, 2006, 2:35pm PST

Summary: You will notice an "auth" variable in the address bar after logging in to your Google Pages account — nothing too exciting right?  Well, this could be a serious security problem just like the one Philipp Lenssen blogged about that affected Google Book Search.  If you paste this entire URL into any browser (even if it’s [...]

You will notice an "auth" variable in the address bar after logging in to your Google Pages account — nothing too exciting right?  Well, this could be a serious security problem just like the one Philipp Lenssen blogged about that affected Google Book Search.  If you paste this entire URL into any browser (even if it’s not logged into your account) you are signed in automatically — no need for a password.  Thankfully this trick doesn’t give you access to any other Google services or the "My Account" area.

I was thinking this may be a feature — a one time or time limited auth string that can be used to log into your account from different browsers or machines, but I’m not certain now that they have fixed the same "problem" in Google Book Search.

As a reminder, just be careful about the URL’s your copying or screenshots you are capturing if the URL has an "auth" variable in it — in some cases it can be just as useful as a password.

 

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Garett Rogers has always had a deep interest in computers and the Internet, which led him to a degree in Computer Information Systems. He is currently employed as a programmer for iQmetrix.

Disclosure

Garett Rogers

Garett Rogers is employed as a programmer for iQmetrix, which specializes in retail management software for the wireless industry. He has no other formal associations with any software or hardware companies.

Biography

Garett Rogers

Garett Rogers has always had a deep interest in computers and the Internet, which led him to a degree in Computer Information Systems. He is currently employed as a programmer for iQmetrix, which specializes in retail management software designed specifically for the cellular and electronics industry.

Garett's journey into Google started with his employer asking him to "get a better rank on Google." Diving into search engine optimization sparked his curiosity for how things work and led him to create a blog dedicated to what interests him most--Google.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

The discussion hasn’t started yet. Why don’t you begin it?

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix