« Google Account Security Breach with Book Search | Main | Google Account Security Breach with Book Search »

February 20, 2006

Google Account Security Breach with Book Search

Philipp Lenssen reports a Google Book Search Security Hole where someone can login to your Google account if they get access, somehow, to your URL string of your Google Book search result page. This is how it works; a person goes to book.google.com does a special search, clicks on a result, logs in and then copies the URL and sends it off to a friend. When the friend gets the URL and clicks on it, it should login the friend to Google as the person who sent the link, giving the friend access to Google Account information that is not his.

Posted by Kevin Heisler at February 20, 2006 8:46 AM

Digg! Digg this! Add to del.icio.us StumbleUpon Toolbar Stumble It!