Google antiphishing site reveals names, passwords
Publicly available blacklist, now with phish food
January 22, 2007 12:00 PM ETIDG News Service - Google Inc. has removed a few usernames and passwords posted inadvertently to a phishing blacklist it compiles and makes publicly available on the Web, the Mountain View, California, company said Monday.
The log-in information was contained in 15 URLs (uniform resource locators) submitted through Google's Firefox toolbar, which lets users report Web pages they suspect to belong to phishing sites. Most of the URLs on the list didn't have log-in information.
Google said it also has implemented a mechanism that detects when a submitted URL contains log-in data and prevents that information from getting posted to the list.
"We are in the process of notifying the users who inadvertently disclosed this information and suggesting that they reset associated passwords," Google said in an e-mailed statement.
Finjan Inc. found the sensitive information on the list and informed Google in early January, the San Jose security vendor said Monday.
In addition to usernames and passwords, the list also included e-mail addresses and session tokens, putting in jeopardy the users' privacy, Finjan said.
Finjan has posted a snapshot of a portion of the list containing the offending URLs, albeit with the sensitive information blacked out.
Users of the Firefox toolbar get a chance to review the suspicious URLs they plan to submit to Google, Google said.
More information about the Safe Browsing feature in Firefox can be obtained on Google's site. The Safe Browsing feature isn't available in Google's Internet Explorer toolbar.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Additional Resources



White Papers & Webcasts
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Email Archiving: A Business-Critical Application
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
IBM ISS X-Force Threat and Risk Report
Learn about all aspects of threats that affect Internet security.
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
The New World of eCrime: Targeted Brand Attacks and How to Combat Them
Download This Whitepaper Now!
The Commercialization of ITIL: Lessons Learned
Register for this event today!
