Spotlight IT Ramblings Blog

I'm living in Dublin, Ireland and this is a collection of ramblings about my day-to-day activities in the exciting world of web development ;-) Technologies used and projects under development. Also links of interest, mostly completely work un-related....

Friday, October 29, 2004

Google Desktop indexes Password protected Office Documents

Just discovered a rather nasty security flaw of Google Desktop, it seems it
gets a bit overzealous in its search to index documents

Create a password protected word or excel document and save it. Give it a
few minutes and then search for the file name or contents. Google desktop
appears to be able to open the file and display the contents regardless of
the encryption. It also displays the 1st few lines of the encrypted file in
the search results and if you click on the "cached" link it can display the
entire contents of the file.

I can only assume Google desktop has indexed the file when its open in Excel
or Word and it doesn't actually crack the encryption on it after its saved
to disk.

When you click on the filename returned in the search results you will get
prompted by word or excel to enter the password as usual.

My only advice is to specifically exclude the paths to any password
protected files. Also exclude paths to any encrypted PGPDisk or TrueCrypt
mapped drives as Google Desktop will also return results in these even when
not mounted.

0 Comments:

Post a Comment

<< Home

 

Valid CSS!
news section


news seperator