Topic: Cross-site scripting

PPC

Update Your All In One SEO Pack WordPress Plugin Now

The Sucuri Blog issued a notice that a popular SEO plugin for WordPress web sites had a major security vulnerability. The plugin name is the “All in One SEO Pack” and the fix is easy, just make sure to update the plugin immediately. The vulnerability opened up WordPress blogs that used the plugin, that had […]

SearchCap: The Day In Search, February 4, 2011

Below is what happened in search today, as reported on Search Engine Land and from other places across the web. From Search Engine Land: Bing: Why Google’s Wrong In Its Accusations Along with everything else going on for Bing’s Harry Shum on Tuesday — a panel about search spam, dealing with Google’s accusations that Bing […]

Google Website Optimizer & Goo.gl URL Security Issues

There are two different security issues around Google products over the past 12 hours or so. The first is with Google Website Optimizer where there was the potential of an Cross-Site Scripting (XSS) attack. The second is with people using Goo.gl, Google’s URL shortener, within Twitter to grab your Twitter passwords. While the second one, […]

Search & Internet Explorer 8

After finally getting the new Internet Explorer 8 beta installed (demands to upgrade Windows, verify Windows, sigh), I spent some time playing with the new search functionality and checking to see if Microsoft was going to try to stack the deck in its favor with the new browser. So far, it remains pretty even handed. […]

June To Be “Month of Search Engines Bugs”

‘Month of bugs’ pins bull’s-eye on Google, Yahoo from Computerworld reports Websecurity.com.ua says it will post a security vulnerability about the most popular search engines of the world each day throughout the month of June, in particular cross-site scripting ones.

Google Desktop Hole Exposed, Fixed

BusinessWeek reports that Google Desktop had a major defect that could have potentially enabled hackers to view personal files on a computer with Google Desktop installed. The hole was plugged February 1st, a few weeks after it was discovered by Watchfire Corp. Google says it has no evidence the vulnerability was exploited.

Using Google Code Search To Find Vulnerable Sites

ShoeMoney wrote a detailed write up on how hackers can easily use Google Code Search to quickly find sites that are vulnerable to being hacked. ShoeMoney shows XSS exploits, SQL injection exploits and more. ShoeMoney wasn’t the first to spot this. SEO Egghead wrote about some examples on October 5th. Is Google to blame? I […]