<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Google Urchin password theft madness</title>
	<atom:link href="http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Sat, 30 Aug 2008 11:03:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Operation n &#187; XSS - Proof of Concept</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-64037</link>
		<dc:creator>Operation n &#187; XSS - Proof of Concept</dc:creator>
		<pubDate>Fri, 02 Nov 2007 07:07:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-64037</guid>
		<description>[...] to redirect to the attacked site) But I mentioning it now because there has been discussions about this already on gnucitizen. This talks bout another a way to send information to a foreign site without [...]</description>
		<content:encoded><![CDATA[<p>[...] to redirect to the attacked site) But I mentioning it now because there has been discussions about this already on gnucitizen. This talks bout another a way to send information to a foreign site without [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-53533</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Fri, 28 Sep 2007 21:56:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-53533</guid>
		<description>Hey MustLive,

Thanks for your kind words, very much appreciated!

I did read about the unauthenticated access issue and left my comments here: http://ha.ckers.org/blog/20070823/xss-and-possible-information-disclosure-in-urchin/

&lt;blockquote&gt;&lt;p&gt;Back in July, when I was searching some examples in Google also noticed that some sites have the Urchin stats wide open, but I thought this was a configuration problem as opposed to a bug.&lt;/p&gt;

&lt;p&gt;Are you guys sure there is a &lt;q&gt;authorization bypass hole&lt;/q&gt;?&lt;/p&gt;&lt;/blockquote&gt;

MustLive, is this a 100% verified issue? Have you guys replicated this in a lab environment? I can't make it work on my test installation.</description>
		<content:encoded><![CDATA[<p>Hey MustLive,</p>
<p>Thanks for your kind words, very much appreciated!</p>
<p>I did read about the unauthenticated access issue and left my comments here: <a href="http://ha.ckers.org/blog/20070823/xss-and-possible-information-disclosure-in-urchin/" rel="nofollow">http://ha.ckers.org/blog/20070.....in-urchin/</a></p>
<blockquote><p>Back in July, when I was searching some examples in Google also noticed that some sites have the Urchin stats wide open, but I thought this was a configuration problem as opposed to a bug.</p>
<p>Are you guys sure there is a <q>authorization bypass hole</q>?</p>
</blockquote>
<p>MustLive, is this a 100% verified issue? Have you guys replicated this in a lab environment? I can&#8217;t make it work on my test installation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-53502</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Fri, 28 Sep 2007 20:14:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-53502</guid>
		<description>Hi Adrian!

No need to paste your words, I read your whole post carefully ;-). I understand that you was first who found this hole and I believe you (and Google also know that you was first who tell them about this XSS). Some people who found this hole after you outstrip you with disclosure, but you was the first discoverer, so you have respect of me and security community.

I understand you with this situation, when other guys officially disclosed your hole before you. This incidents sometimes happens in webappsec world. I regularly have such experience, when people disclosing holes which I first discover before me, or when people disclosing holes many months after my disclosure.

What I wrote in my previous comment (and what I wrote at my site), that there is another hole in Urchin. It is Authorization bypass vulnerability (which as I know was found by RSnake and you didn't mention it in your post). This one gives possibility to enter into account without any login and password. It is also interesting hole as your XSS.</description>
		<content:encoded><![CDATA[<p>Hi Adrian!</p>
<p>No need to paste your words, I read your whole post carefully ;-). I understand that you was first who found this hole and I believe you (and Google also know that you was first who tell them about this XSS). Some people who found this hole after you outstrip you with disclosure, but you was the first discoverer, so you have respect of me and security community.</p>
<p>I understand you with this situation, when other guys officially disclosed your hole before you. This incidents sometimes happens in webappsec world. I regularly have such experience, when people disclosing holes which I first discover before me, or when people disclosing holes many months after my disclosure.</p>
<p>What I wrote in my previous comment (and what I wrote at my site), that there is another hole in Urchin. It is Authorization bypass vulnerability (which as I know was found by RSnake and you didn&#8217;t mention it in your post). This one gives possibility to enter into account without any login and password. It is also interesting hole as your XSS.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A rough week for Google security &#8212; Security Bytes</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-53244</link>
		<dc:creator>A rough week for Google security &#8212; Security Bytes</dc:creator>
		<pubDate>Fri, 28 Sep 2007 00:10:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-53244</guid>
		<description>[...] An Urchin Login XSS disclosed by GNUCITIZENâ€™s Adrian Pastor, which could be exploited to compromise local Google [...]</description>
		<content:encoded><![CDATA[<p>[...] An Urchin Login XSS disclosed by GNUCITIZENâ€™s Adrian Pastor, which could be exploited to compromise local Google [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: [SSD] Security &#38; Development Blog &#187; ColecciÃ³n de vulnerabilidades XSS en aplicaciones de Google</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52999</link>
		<dc:creator>[SSD] Security &#38; Development Blog &#187; ColecciÃ³n de vulnerabilidades XSS en aplicaciones de Google</dc:creator>
		<pubDate>Thu, 27 Sep 2007 03:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52999</guid>
		<description>[...] se mencionan otras dos vulnerabilidades XSS ([1], [2]) dentro de las pÃ¡ginas de Picasa Web y las que utilizan el software instalable de [...]</description>
		<content:encoded><![CDATA[<p>[...] se mencionan otras dos vulnerabilidades XSS ([1], [2]) dentro de las pÃ¡ginas de Picasa Web y las que utilizan el software instalable de [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eBusiness Industry News &#187; Blog Archive &#187; Bullseye on Google: Hackers expose holes in GMail, Blogspot, Search Appliance</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52948</link>
		<dc:creator>eBusiness Industry News &#187; Blog Archive &#187; Bullseye on Google: Hackers expose holes in GMail, Blogspot, Search Appliance</dc:creator>
		<pubDate>Wed, 26 Sep 2007 19:07:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52948</guid>
		<description>[...] bug in Googleâ€™s Urchin Analytics service that can be exploited to steal user credentials. An explanation of this vulnerability has been published by Adrian [...]</description>
		<content:encoded><![CDATA[<p>[...] bug in Googleâ€™s Urchin Analytics service that can be exploited to steal user credentials. An explanation of this vulnerability has been published by Adrian [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Linux-OS &#187; Semana negra para Google</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52889</link>
		<dc:creator>Linux-OS &#187; Semana negra para Google</dc:creator>
		<pubDate>Wed, 26 Sep 2007 12:45:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52889</guid>
		<description>[...] Adrian Pastor, de GNU Citizen, publica una nueva vulnerabilidad XSS explotable (robo de contraseÃ±as) en la pÃ¡gina de login de Google Urchin Web Analytics 5, es [...]</description>
		<content:encoded><![CDATA[<p>[...] Adrian Pastor, de GNU Citizen, publica una nueva vulnerabilidad XSS explotable (robo de contraseÃ±as) en la pÃ¡gina de login de Google Urchin Web Analytics 5, es [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DigitMemo.com &#187; Hackers expose holes in GMail, Blogspot, Search Appliance</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52689</link>
		<dc:creator>DigitMemo.com &#187; Hackers expose holes in GMail, Blogspot, Search Appliance</dc:creator>
		<pubDate>Wed, 26 Sep 2007 00:09:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52689</guid>
		<description>[...] bug in Googleâ€™s Urchin Analytics service that can be exploited to steal user credentials. An explanation of this vulnerability has been published by Adrian Pastor.   From: DigitMemo.com   [...]</description>
		<content:encoded><![CDATA[<p>[...] bug in Googleâ€™s Urchin Analytics service that can be exploited to steal user credentials. An explanation of this vulnerability has been published by Adrian Pastor.   From: DigitMemo.com   [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hackers expose holes in GMail, Blogspot, Search Appliance &#124; xMoDx</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52679</link>
		<dc:creator>Hackers expose holes in GMail, Blogspot, Search Appliance &#124; xMoDx</dc:creator>
		<pubDate>Tue, 25 Sep 2007 23:23:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52679</guid>
		<description>[...] bug in Googleâ€™s Urchin Analytics service that can be exploited to steal user credentials. An explanation of this vulnerability has been published by Adrian [...]</description>
		<content:encoded><![CDATA[<p>[...] bug in Googleâ€™s Urchin Analytics service that can be exploited to steal user credentials. An explanation of this vulnerability has been published by Adrian [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Naraine&#8217;s Zero Day mobile edition</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52606</link>
		<dc:creator>Ryan Naraine&#8217;s Zero Day mobile edition</dc:creator>
		<pubDate>Tue, 25 Sep 2007 20:06:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52606</guid>
		<description>[...] bug in Google&#8217;s Urchin Analytics service that can be exploited to steal user credentials. An explanation of this vulnerability has been published by Adrian [...]</description>
		<content:encoded><![CDATA[<p>[...] bug in Google&#8217;s Urchin Analytics service that can be exploited to steal user credentials. An explanation of this vulnerability has been published by Adrian [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52434</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Tue, 25 Sep 2007 10:11:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52434</guid>
		<description>Hi MustLive:

Copied and pasted from this very same post:

&lt;blockquote&gt;I reported the issue to Google back on Jul 25 and was confirmed by their security team. They are now working on a fix. My original plan was to publish this info after a fix would be released. However, the issue has also been found by other folks about a month ago.&lt;/blockquote&gt;

In other words, I do mention that it's been publicly made a month ago by others, but ALSO that I reported it to Google 2 months ago and that I was waiting for them to fix it BEFORE making it public.</description>
		<content:encoded><![CDATA[<p>Hi MustLive:</p>
<p>Copied and pasted from this very same post:</p>
<blockquote><p>I reported the issue to Google back on Jul 25 and was confirmed by their security team. They are now working on a fix. My original plan was to publish this info after a fix would be released. However, the issue has also been found by other folks about a month ago.</p></blockquote>
<p>In other words, I do mention that it&#8217;s been publicly made a month ago by others, but ALSO that I reported it to Google 2 months ago and that I was waiting for them to fix it BEFORE making it public.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: djteller</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52429</link>
		<dc:creator>djteller</dc:creator>
		<pubDate>Tue, 25 Sep 2007 10:00:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52429</guid>
		<description>Nice work man.
Sorry about the credit issue, but dont worry, you got our respect.</description>
		<content:encoded><![CDATA[<p>Nice work man.<br />
Sorry about the credit issue, but dont worry, you got our respect.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52310</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Tue, 25 Sep 2007 01:17:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52310</guid>
		<description>Adrian.

As I wrote at my site month ago (http://websecurity.com.ua/1283/) about this XSS hole  in Urchin, RSnake already wrote about this hole. Like you also mentioned about. But as I and RSnake wrote, there is not only XSS, but also Authorization bypass vulnerability in Urchin. Which give possibility to look at statistic without any login and password!

&lt;blockquote&gt;I know that youâ€™re sick of XSS PoCs that only open alert boxes.&lt;/blockquote&gt;
I'm not, I like alert boxes :-), especially alert(document.cookie).

Nevertheless, man, nice XSS PoCs and video ;-).</description>
		<content:encoded><![CDATA[<p>Adrian.</p>
<p>As I wrote at my site month ago (http://websecurity.com.ua/1283/) about this XSS hole  in Urchin, RSnake already wrote about this hole. Like you also mentioned about. But as I and RSnake wrote, there is not only XSS, but also Authorization bypass vulnerability in Urchin. Which give possibility to look at statistic without any login and password!</p>
<blockquote><p>I know that youâ€™re sick of XSS PoCs that only open alert boxes.</p></blockquote>
<p>I&#8217;m not, I like alert boxes :-), especially alert(document.cookie).</p>
<p>Nevertheless, man, nice XSS PoCs and video ;-).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: [SSD] Security &#38; Development Blog &#187; Semana negra para Google</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52261</link>
		<dc:creator>[SSD] Security &#38; Development Blog &#187; Semana negra para Google</dc:creator>
		<pubDate>Mon, 24 Sep 2007 22:15:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52261</guid>
		<description>[...] Adrian Pastor, de GNU Citizen, publica una nueva vulnerabilidad XSS explotable (robo de contraseÃ±as) en la pÃ¡gina de login de Google Urchin Web Analytics 5, es [...]</description>
		<content:encoded><![CDATA[<p>[...] Adrian Pastor, de GNU Citizen, publica una nueva vulnerabilidad XSS explotable (robo de contraseÃ±as) en la pÃ¡gina de login de Google Urchin Web Analytics 5, es [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DigitMemo.com &#187; Multi Google Security Holes Revealed</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52246</link>
		<dc:creator>DigitMemo.com &#187; Multi Google Security Holes Revealed</dc:creator>
		<pubDate>Mon, 24 Sep 2007 21:14:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52246</guid>
		<description>[...] , The Urchin Login XSS, another Google-outsourced vulnerability, could compromise local Google Analytics installations. [...]</description>
		<content:encoded><![CDATA[<p>[...] , The Urchin Login XSS, another Google-outsourced vulnerability, could compromise local Google Analytics installations. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Passwortklau mit XSS und &#8220;autocomplete passwords&#8221; &#187; darkster.de</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52215</link>
		<dc:creator>Passwortklau mit XSS und &#8220;autocomplete passwords&#8221; &#187; darkster.de</dc:creator>
		<pubDate>Mon, 24 Sep 2007 18:47:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52215</guid>
		<description>[...] Madness? This is gnucitizen.org. [...]</description>
		<content:encoded><![CDATA[<p>[...] Madness? This is gnucitizen.org. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net Â» GoogHOle (XSS pwning GMail, Picasa and almost 200K customers)</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52180</link>
		<dc:creator>hackademix.net Â» GoogHOle (XSS pwning GMail, Picasa and almost 200K customers)</dc:creator>
		<pubDate>Mon, 24 Sep 2007 17:15:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52180</guid>
		<description>[...] after I released the first version of article, I read of another Google-outsourced vulnerability: Urchin Login XSS disclosed by GNUCITIZEN&#8217;s Adran Pastor, which could compromise local Google Analytics [...]</description>
		<content:encoded><![CDATA[<p>[...] after I released the first version of article, I read of another Google-outsourced vulnerability: Urchin Login XSS disclosed by GNUCITIZEN&#8217;s Adran Pastor, which could compromise local Google Analytics [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RobotSkirts &#187; Blog Archive &#187; Google Urchin password theft madness</title>
		<link>http://www.gnucitizen.org/blog/google-urchin-password-theft-madness/#comment-52175</link>
		<dc:creator>RobotSkirts &#187; Blog Archive &#187; Google Urchin password theft madness</dc:creator>
		<pubDate>Mon, 24 Sep 2007 16:41:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-urchin-password-theft-madness#comment-52175</guid>
		<description>[...] Google Urchin password theft madness XSS attack that steals autocomplete information from the login screen before the user even clicks login. [...]</description>
		<content:encoded><![CDATA[<p>[...] Google Urchin password theft madness XSS attack that steals autocomplete information from the login screen before the user even clicks login. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
