Short Name |
HTTP:STC:IE:GOOGLEBAR-FILE |
---|---|
Severity |
Low |
Recommended |
No |
Category |
HTTP |
Keywords |
GoogleBar Arbitrary Local File Access |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability in the Google ToolBar, an Internet Explorer plugin. Google ToolBar 1.1.58 and prior are vulnerable. The configuration URL that is used make changes to Google ToolBar option is available only to documents within google.com or a special res:// protocol. Attackers can open a browser window that uses google.com or any res:// as a URL, then use scripting to change the URL to the Google ToolBar configuration URL. Once they have gained access, they cAN view any local files that can be opened with Internet Explorer.
The Google Toolbar is an ActiveX control for Microsoft Internet Explorer, which provides functionality related to the Google search engine. It is possible to modify configuration settings by visiting a specific URL that accepts commands as CGI parameters. A malicious script may directly access this URL by redirecting a page which references a trusted site, such as the google.com domain. It is possible to modify the toolbar configuration, and to execute arbitrary script code, possibly within the Local System security zone.