Security Flaw in Google Reader Added Subscribers Without Intent

Jul 19, 2007 - 9:27 am 0 by
Filed Under Misc Google

A DigitalPoint Forums member points to a vulnerability within Google Reader that enables blog owners to add code to their blog that will allow any visitor to automatically subscribe to the RSS feed. Patrick Altoft wrote about this discovery and says that if you copy certain code to your site and a user has logged into his/her account, they will automatically be subscribed to your blog:

The problem is that unscrupulous websites can copy the links to Add to Google homepage or Add to Google Reader and open them up in an IFRAME for every visitor, meaning that anybody who visits their website while signed in to a Google account will suddenly have subscribed to the RSS feed on both Google Reader and the Google homepage automatically.

I tried Patrick's demo and it seems to have been fixed. In fact, Matt Cutts responded as well and it appears that the hole has been patched.

In any event, if you want to subscribe to our feeds (and we know you do), we have two RSS feeds (a normal feed and a full feed) and one email feed. You're welcome to Subscribe to any of our feeds.

Forum discussion at DigitalPoint Forums.

 

Popular Categories

The Pulse of the search community

Follow

Search Video Recaps

 
Gvolatility, Bing Generative Search, Reddit Blocks Bing, Sticky Cookies, AI Overview Ads & SearchGPT - YouTube
Video Details More Videos Subscribe to Videos

Most Recent Articles

Search Forum Recap

Daily Search Forum Recap: July 26, 2024

Jul 26, 2024 - 10:00 am
Search Video Recaps

Google Volatility, Bing Generative Search, Reddit Blocks Bing, Sticky Cookies, AI Overview Ads & SearchGPT

Jul 26, 2024 - 8:01 am
Google

Google Gemini Adds Related Content & Verification Links

Jul 26, 2024 - 7:51 am
Other Search Engines

SearchGPT - OpenAI's AI Search Tool

Jul 26, 2024 - 7:41 am
Search Engine Optimization

Google's John Mueller: Don't Use LLMs For SEO Advice

Jul 26, 2024 - 7:31 am
Google

Google Search With Related Images Carousel Below Image Box

Jul 26, 2024 - 7:21 am
Previous Story: Yahoo! Acquires Stake in Tyroo, an Indian Online Advertising Agency