In association with heise online

19 December 2007, 16:31

Unsafe buttons in Google's toolbar

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

The Google Toolbar allows vendors and websites to install additional buttons, for example, to make it easier to search through their sites. However, security researcher Aviv Raff has discovered that an attacker can spoof information displayed during installation, both the origin of the button and the domain it exchanges information with. This simplifies attacks as criminals could use the button to conduct phishing attacks or persuade users to download and run programs from what they mistakenly believe is a trusted domain.

Attackers can fool the Google Toolbar by using a redirection, for example Google's publicly accessible redirector function, to enter a fake URL as the source for the installation files: The Toolbar for Internet Explorer allows an attacker to fake the domains displayed under Downloaded from and Privacy considerations. In the Firefox version it is only possible to display a fake domain under Privacy considerations.

The Google Toolbar lets you to install custom buttons
Zoom Custom buttons in the Google Toolbar can conceal their provenance.

Raff has provided a proof-of-concept on his server. If you click on the link you are asked if you want to install a button from Google containing data from the domain The button is actually from Raff's server, Once the button is installed and you click on it, you will download a file, although Internet Explorer will now show you the real domain hosting the file. However, a user who is not paying close attention at this point could easily download and install a trojan or similar.

But downloads via the Toolbar reveal their true origin
Zoom IE shows the real address of downloads started by the button.

Raff's security report states that Google has already been informed of the problem and is working on a fix. Until then, it is recommended that you avoid installing any new buttons in the toolbar.

See also:


Print Version | Send by email | Permalink:

  • July's Community Calendar

The H Open

The H Security

The H Developer

The H Internet Toolkit