ICT Security-Sécurité PC et Internet
87.1K views | +0 today
ICT Security-Sécurité PC et Internet
ICT Security + Privacy + Piracy + Data Protection - Censorship - Des cours et infos gratuites sur la"Sécurité PC et Internet" pour usage non-commercial... (FR, EN+DE)...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Scooped by Gust MEES
Scoop.it!

Grammarly's flawed Chrome extension exposed users' private documents | #CyberSecurity #Privacy #DataBreaches #DataBreaches #Awareness

Grammarly's flawed Chrome extension exposed users' private documents | #CyberSecurity #Privacy #DataBreaches #DataBreaches #Awareness | ICT Security-Sécurité PC et Internet | Scoop.it


Grammarly has fixed a security bug in its Chrome extension that inadvertently allowed access to a user's account -- including their private documents and data.

Tavis Ormandy, a security researcher at Google's Project Zero who found the "high severity" vulnerability, said the browser extension exposed authentication tokens to all websites.

That means any website can access a user's documents, history, logs, and other data, the bug report said.

"I'm calling this a high severity bug, because it seems like a pretty severe violation of user expectations," said Ormandy, because "users would not expect that visiting a website gives it permission to access documents or data they've typed into other websites."

In proof-of-concept code, he explained how to trigger the bug in four lines of code.

More than 22 million users have installed the grammar-checking extension.

Ormandy filed his bug report Friday, subject to a 90-day disclosure deadline -- as is the industry standard. Grammarly issued an automatic update Monday to fix the issue.

Ormandy has in recent months examined several vulnerable web browser extensions. Earlier this year, he found a remote code execution flaw in the Cisco WebEx Chrome extension, and a data-stealing bug in the popular LastPass password manager.

A spokesperson for Grammarly did not immediately return a request for comment.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=DATA-BREACHES

 

 

Gust MEES's insight:

Grammarly has fixed a security bug in its Chrome extension that inadvertently allowed access to a user's account -- including their private documents and data.

Tavis Ormandy, a security researcher at Google's Project Zero who found the "high severity" vulnerability, said the browser extension exposed authentication tokens to all websites.

That means any website can access a user's documents, history, logs, and other data, the bug report said.

"I'm calling this a high severity bug, because it seems like a pretty severe violation of user expectations," said Ormandy, because "users would not expect that visiting a website gives it permission to access documents or data they've typed into other websites."

In proof-of-concept code, he explained how to trigger the bug in four lines of code.

More than 22 million users have installed the grammar-checking extension.

Ormandy filed his bug report Friday, subject to a 90-day disclosure deadline -- as is the industry standard. Grammarly issued an automatic update Monday to fix the issue.

Ormandy has in recent months examined several vulnerable web browser extensions. Earlier this year, he found a remote code execution flaw in the Cisco WebEx Chrome extension, and a data-stealing bug in the popular LastPass password manager.

A spokesperson for Grammarly did not immediately return a request for comment.

 

Learn more / En savoir plus / Mehr erfahren:

 

https://www.scoop.it/t/securite-pc-et-internet/?&tag=DATA-BREACHES

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

Microsoft warns users of new malicious Chrome extension and Firefox add-on that hijack Facebook accounts

Microsoft warns users of new malicious Chrome extension and Firefox add-on that hijack Facebook accounts | ICT Security-Sécurité PC et Internet | Scoop.it
Microsoft has discovered a new piece of malware in the form of a Google Chrome extension and Firefox add-on that can hijack Facebook accounts. It does not appear that there are equivalent ...
Gust MEES's insight:

 

Download ONLY from the official places!!!

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

Google verbessert Sicherheit bei Chrome Add-ons - internetmagazin - Magnus.de

Google verbessert Sicherheit bei Chrome Add-ons - internetmagazin - Magnus.de | ICT Security-Sécurité PC et Internet | Scoop.it
Google führt derzeit schrittweise eine Content-Security-Policy (CSP) ein, ein System zur Verbesserung der Sicherheit bei Browsererweiterungen.
No comment yet.
Scooped by Gust MEES
Scoop.it!

Trojaner entführt Facebook-Konten

Trojaner entführt Facebook-Konten | ICT Security-Sécurité PC et Internet | Scoop.it
Microsoft warnt vor einem neu entdeckten Trojaner, der auf Facebook-Nutzer abzielt und deren Konten kapert.
Gust MEES's insight:

 

Trojaner entführt Facebook-Konten

 

Gust MEES's curator insight, May 13, 2013 3:07 PM

 

Trojaner entführt Facebook-Konten


Scooped by Gust MEES
Scoop.it!

Böse Trojaner in Erweiterungen für Chrome-Browser

Böse Trojaner in Erweiterungen für Chrome-Browser | ICT Security-Sécurité PC et Internet | Scoop.it
Die Sicherheitsexperten von Kaspersky warnen vor gefährlichen Erweiterungen für Google Chrome, die über den offiziellen Chrome Web Store verbreitet werden.
No comment yet.
Scooped by Gust MEES
Scoop.it!

Chrome add-on allows remote computer control | Desktop Apps | ZDNet UK

Chrome add-on allows remote computer control | Desktop Apps | ZDNet UK | ICT Security-Sécurité PC et Internet | Scoop.it
Google has released an extension for Chrome that allows people to use the browser to take remote control of another computer.
No comment yet.