Collected research
Google Translate - Google User Content - File Uploading Cross - XSS and Design Stringency - A Talk
Google Translate - Google User Content - File Uploading Cross - XSS and Design Stringency
Files uploaded to Google Translate were rendered on translate.googleusercontent.com with their scripts and iframes intact, so translated attacker content executed in a Google-hosted context. Google treated it as by design; the post argues users read translation as trustworthy and asks for a Bing-style untrusted-content notice.
Record
- Document
- Google Translate - Google User Content - File Uploading Cross - XSS and Design Stringency
- Researcher
- Aditya K Sood
- Published by
- zeroknock.blogspot.com
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .