Web Hack List

Collected research

Google Translate - Google User Content - File Uploading Cross - XSS and Design Stringency - A Talk

Google Translate - Google User Content - File Uploading Cross - XSS and Design Stringency

Files uploaded to Google Translate were rendered on translate.googleusercontent.com with their scripts and iframes intact, so translated attacker content executed in a Google-hosted context. Google treated it as by design; the post argues users read translation as trustworthy and asks for a Bing-style untrusted-content notice.

Record

Document
Google Translate - Google User Content - File Uploading Cross - XSS and Design Stringency
Researcher
Aditya K Sood
Published by
zeroknock.blogspot.com
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .