Уровень 0 · материалов: 2
В кластер входят документы об уязвимостях в инструментах Google (Forms, Spreadsheets), но не входят документы об общих методах манипуляции просмотрами через теги изображений.
Общие признаки: ошибки безопасности Google Forms и Spreadsheets, манипуляция функциями для эксфильтрации данных, злоупотребление ботами Google, обход фильтров ввода
Группа выше: Уязвимости конкретных продуктов и платформ
Смысл: The main idea is that a flaw in how Google Spreadsheet's =image() function handles URLs allows a user to weaponize Google's FeedFetcher bot to perform high-bandwidth HTTP GET flood attacks on any website, which Google refuses to acknowledge as a security vulnerability.
An attacker can use the =image() function in Google Spreadsheets with randomized URL parameters to trick Google's FeedFetcher bot into performing a massive DDoS attack on a target server.
Смысл: The main idea is the discovery and reporting of a Formula Injection vulnerability in Google Forms, where attackers could bypass input filters to execute functions that exfiltrate data from spreadsheets to external servers.
Security researchers found a way to inject executable formulas into Google Forms by using a backspace character to bypass filters, allowing for potential data theft from the resulting spreadsheets.