CHINA TOPIX

05/16/2024 10:45:02 pm

Make CT Your Homepage

Google Cloud Releases Security Scanner for Web Applications

google-project-zero

Google's Project Zero is loosening its rules regarding vulnerability disclosure.

In a recent blog, Google has announced its cloud platform will conduct security scans on web applications.

The Google Cloud Security Scanner is currently in its beta stage. Basically, the scanner will look for at least two common security errors. This is accomplished by examining the cross-site scripting otherwise known as XSS, as well as the application's contents.

Like Us on Facebook

The blog explained the scanner will not entangle itself with HTML5 and JavaScript codes.  Rather, the program will first scan the application by parsing the html codes and then conduct a more thorough search among the more intricate sections of the application's codes.

Google's security manager Rob Mann said in his blog the scanner will work through the Google Compute Engine and will, in effect, "create a botnet of hundreds of virtual Chrome workers to scan your site".

The scanner will behave like a hacker trying to find and exploit the weakness in the web site. It will only test the vulnerabilities of the site in a "safe way" and will not compromise its security.  

While this kind of effort from the giant search engine is laudable, it has also made some people and companies unhappy about having their application's security flaws exposed. 

One such company is Microsoft, where Google has exposed a number of bugs in several of its web applications. In one instance, Google discovered another bug in one of Microsoft's web application and claimed the Windows giant was not making any effort to close the security breach.

Lately, both Microsoft and Google have agreed to work jointly on handling false positive virus flags, which are currently plaguing developers and users alike.

Google, on the other hand, is itself unwilling to fix a security flaw in the older Android versions that comprise more than a half of the total Android market.

Real Time Analytics