Google develops Web app security tool

By Tom Espiner, ZDNet UK
Friday, July 20, 2007 11:30 AM

Google is in the process of developing a security tool to automatically find cross-site scripting holes in its Web applications.

Code-named "Lemon", which Google says is derived from the term for a defective product, the tool works by fuzz testing or fault-injection, which brute-force tests by supplying random data inputs that are designed to trigger and expose flaws in Web applications. Lemon is a black box tester, which assumes no knowledge of the internal structure of an application or device.

According to Google security team member Srinath Anantharaju, Lemon has been developed to detect cross-site scripting (XXS) vulnerabilities, but Google is "in the process of adding new attack vectors to improve the tool against [other] known security problems".

"Our vulnerability testing tool enumerates a Web application's URLs and corresponding input parameters," wrote Anantharaju in the Google online security blog. "It then iteratively supplies fault strings designed to expose XSS and other vulnerabilities to each input, and analyses the resulting responses for evidence of such vulnerabilities."

XSS attacks generally work by injecting code into Web applications for malicious purposes. An attacker can inject code into a Web application, which is then executed in a user's browser session. Hackers can also compromise users by sending an e-mail with a crafted malicious URL that, when clicked on, loads a Webpage and injected script that executes in a browser session.

Google plans to use the tool to test its own Web applications, and will not be releasing Lemon in the near future as it is "highly customized" for those applications, according to Anantharaju. The Google security team evaluated commercially available fuzzers, but felt the company's "specialized needs could be served best by developing our own tools".

Various open-source fuzzers are available online, while commercial fuzzers are also available.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Output local group membership on Windows Server

Windows Server

Command line skills for Windows Servers are essential to deliver information without wasting time. Here's how an old tool and a new tool can help.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except that..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web