[{"@context":"https:\/\/schema.org\/","@type":"BlogPosting","@id":"https:\/\/blog.onlinemarketing.dk\/google-website-optimizer-sikkerhedsproblem.html#BlogPosting","mainEntityOfPage":"https:\/\/blog.onlinemarketing.dk\/google-website-optimizer-sikkerhedsproblem.html","headline":"Google website optimizer sikkerhedsproblem","name":"Google website optimizer sikkerhedsproblem","description":"Google website optimizer sikkerhedsproblem Google har rundsendt information om et sikkerhedshul i deres website optimizer. Det nuv\u00e6rende script indeholder en sikkerhedsbrist, som kan f\u00f8re til&hellip;","datePublished":"2010-12-09","dateModified":"2010-12-09","author":{"@type":"Person","@id":"https:\/\/blog.onlinemarketing.dk\/author\/admin#Person","name":"admin","url":"https:\/\/blog.onlinemarketing.dk\/author\/admin","identifier":1,"image":{"@type":"ImageObject","@id":"https:\/\/secure.gravatar.com\/avatar\/ce65f41ecd392d9b2ef547aba58da9858a8cfb78bd54ce7a6acbffad581f31b2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/ce65f41ecd392d9b2ef547aba58da9858a8cfb78bd54ce7a6acbffad581f31b2?s=96&d=mm&r=g","height":96,"width":96}},"publisher":{"@type":"Organization","name":"Online Marketing","logo":{"@type":"ImageObject","@id":"https:\/\/blog.onlinemarketing.dk\/wp-content\/uploads\/2017\/05\/onlinemarketing_logo_mini.gif","url":"https:\/\/blog.onlinemarketing.dk\/wp-content\/uploads\/2017\/05\/onlinemarketing_logo_mini.gif","width":600,"height":60}},"image":{"@type":"ImageObject","@id":"https:\/\/blog.onlinemarketing.dk\/wp-content\/uploads\/2017\/05\/onlinemarketing_medium.gif","url":"https:\/\/blog.onlinemarketing.dk\/wp-content\/uploads\/2017\/05\/onlinemarketing_medium.gif","width":100,"height":100},"url":"https:\/\/blog.onlinemarketing.dk\/google-website-optimizer-sikkerhedsproblem.html","about":["Google"],"wordCount":819,"articleBody":"Google website optimizer sikkerhedsproblemGoogle har rundsendt information om et sikkerhedshul i deres website optimizer.Det nuv\u00e6rende script indeholder en sikkerhedsbrist, som kan f\u00f8re til at der kan foretages cross-site scripting p\u00e5 det p\u00e5g\u00e6ldende website.Google anbefaler sine brugere enten at slette eksisterende eksperimenter eller at tilpasse det eksisterende script, s\u00e5ledes det forhindrer uautoriseret adgang via website optimizer scriptet, hvor ondsindede kan f\u00e5 adgang til websitet med cross-site scripting.Nye eksperimenter er ikke s\u00e5rbare overfor cross-site scripting.Find website optimizer control scriptet p\u00e5 dit website, hvis du \u00f8nsker manuelt at redigere i det og beholde allerede eksisterende eksperimenter.:A\/B Test Control Script&lt;!&#8211; Google Website Optimizer Control Script &#8211;&gt;&lt;script&gt;function utmx_section(){}function utmx(){}(function(){var k=&#8217;XXXXXXXXXX&#8217;,d=document,l=d.location,c=d.cookie;function f(n){if(c){var i=c.indexOf(n+&#8217;=&#8217;);if(i&gt;-1){var j=c.indexOf(&#8216;;&#8217;,i);return c.substring(i+n.length+1,j&lt;0?c.length:j)}}}var x=f(&#8216;__utmx&#8217;),xx=f(&#8216;__utmxx&#8217;),h=l.hash;d.write(&#8216;&lt;sc&#8217;+&#8217;ript src=&#8221;&#8216;+&#8216;http&#8217;+(l.protocol==&#8217;https:&#8217;?&#8217;s:\/\/ssl&#8217;:&#8217;:\/\/www&#8217;)+&#8217;.google-analytics.com&#8217;+&#8217;\/siteopt.js?v=1&amp;utmxkey=&#8217;+k+&#8217;&amp;utmx=&#8217;+(x?x:&#8221;)+&#8217;&amp;utmxx=&#8217;+(xx?xx:&#8221;)+&#8217;&amp;utmxtime=&#8217;+new Date().valueOf()+(h?&#8217;&amp;utmxhash=&#8217;+escape(h.substr(1)):&#8221;)+&#8216;&#8221; type=&#8221;text\/javascript&#8221; charset=&#8221;utf-8&#8243;&gt;&lt;\/sc&#8217;+&#8217;ript&gt;&#8217;)})();&lt;\/script&gt;&lt;script&gt;utmx(&#8220;url&#8221;,&#8217;A\/B&#8217;);&lt;\/script&gt;&lt;!&#8211; End of Google Website Optimizer Control Script &#8211;&gt; Multivariate Test Control Script&lt;!&#8211; Google Website Optimizer Control Script &#8211;&gt;&lt;script&gt;function utmx_section(){}function utmx(){}(function(){var k=&#8217;XXXXXXXXXX&#8217;,d=document,l=d.location,c=d.cookie;function f(n){if(c){var i=c.indexOf(n+&#8217;=&#8217;);if(i&gt;-1){var j=c.indexOf(&#8216;;&#8217;,i);return c.substring(i+n.length+1,j&lt;0?c.length:j)}}}var x=f(&#8216;__utmx&#8217;),xx=f(&#8216;__utmxx&#8217;),h=l.hash;d.write(&#8216;&lt;sc&#8217;+&#8217;ript src=&#8221;&#8216;+&#8216;http&#8217;+(l.protocol==&#8217;https:&#8217;?&#8217;s:\/\/ssl&#8217;:&#8217;:\/\/www&#8217;)+&#8217;.google-analytics.com&#8217;+&#8217;\/siteopt.js?v=1&amp;utmxkey=&#8217;+k+&#8217;&amp;utmx=&#8217;+(x?x:&#8221;)+&#8217;&amp;utmxx=&#8217;+(xx?xx:&#8221;)+&#8217;&amp;utmxtime=&#8217;+new Date().valueOf()+(h?&#8217;&amp;utmxhash=&#8217;+escape(h.substr(1)):&#8221;)+&#8216;&#8221; type=&#8221;text\/javascript&#8221; charset=&#8221;utf-8&#8243;&gt;&lt;\/sc&#8217;+&#8217;ript&gt;&#8217;)})();&lt;\/script&gt;&lt;!&#8211; End of Google Website Optimizer Control Script &#8211;&gt; Find denne linje i Google website optimizer scriptet: return c.substring(&#8230;Modficer denne linje:F\u00f8r: return c.substring(i+n.length+1,j&lt;0?c.length:j)Efter: return escape(c.substring(i+n.length+1,j&lt;0?c.length:j))Husk afslutningen med parantes. \u201c)\u201d Fixed A\/B Control Script&lt;!&#8211; Google Website Optimizer Control Script &#8211;&gt;&lt;script&gt;function utmx_section(){}function utmx(){} (function(){var k=&#8217;XXXXXXXXXX&#8217;,d=document,l=d.location,c=d.cookie;function f(n){ if(c){var i=c.indexOf(n+&#8217;=&#8217;);if(i&gt;-1){var j=c.indexOf(&#8216;;&#8217;,i);return escape(c.substring(i+n.length+1,j&lt;0?c.length:j))}}}var x=f(&#8216;__utmx&#8217;),xx=f(&#8216;__utmxx&#8217;),h=l.hash; d.write(&#8216;&lt;sc&#8217;+&#8217;ript src=&#8221;&#8216;+&#8216;http&#8217;+(l.protocol==&#8217;https:&#8217;?&#8217;s:\/\/ssl&#8217;:&#8217;:\/\/www&#8217;)+&#8217;.google-analytics.com&#8217;+&#8217;\/siteopt.js?v=1&amp;utmxkey=&#8217;+k+&#8217;&amp;utmx=&#8217;+(x?x:&#8221;)+&#8217;&amp;utmxx=&#8217;+(xx?xx:&#8221;)+&#8217;&amp;utmxtime=&#8217;+new Date().valueOf()+(h?&#8217;&amp;utmxhash=&#8217;+escape(h.substr(1)):&#8221;)+&#8216;&#8221; type=&#8221;text\/javascript&#8221; charset=&#8221;utf-8&#8243;&gt;&lt;\/sc&#8217;+&#8217;ript&gt;&#8217;)})();&lt;\/script&gt;&lt;script&gt;utmx(&#8220;url&#8221;,&#8217;A\/B&#8217;);&lt;\/script&gt;&lt;!&#8211; End of Google Website Optimizer Control Script &#8211;&gt;Fixed Multivariate Control Script&lt;!&#8211; Google Website Optimizer Control Script &#8211;&gt;&lt;script&gt;function utmx_section(){}function utmx(){}(function(){var k=&#8217;XXXXXXXXXX&#8217;,d=document,l=d.location,c=d.cookie;function f(n){if(c){var i=c.indexOf(n+&#8217;=&#8217;);if(i&gt;-1){var j=c.indexOf(&#8216;;&#8217;,i);return escape(c.substring(i+n.length+1,j&lt;0?c.length:j))}}}var x=f(&#8216;__utmx&#8217;),xx=f(&#8216;__utmxx&#8217;),h=l.hash; d.write(&#8216;&lt;sc&#8217;+&#8217;ript src=&#8221;&#8216;+&#8216;http&#8217;+(l.protocol==&#8217;https:&#8217;?&#8217;s:\/\/ssl&#8217;:&#8217;:\/\/www&#8217;)+&#8217;.google-analytics.com&#8217;+&#8217;\/siteopt.js?v=1&amp;utmxkey=&#8217;+k+&#8217;&amp;utmx=&#8217;+(x?x:&#8221;)+&#8217;&amp;utmxx=&#8217;+(xx?xx:&#8221;)+&#8217;&amp;utmxtime=&#8217;+new Date().valueOf()+(h?&#8217;&amp;utmxhash=&#8217;+escape(h.substr(1)):&#8221;)+&#8216;&#8221; type=&#8221;text\/javascript&#8221; charset=&#8221;utf-8&#8243;&gt;&lt;\/sc&#8217;+&#8217;ript&gt;&#8217;)})();&lt;\/script&gt;&lt;!&#8211; End of Google Website Optimizer Control Script &#8211;&gt;Bem\u00e6rk=XXXXXXXXX linjen er en placeholder i control scriptet.Eksperiment vil forts\u00e6tte som normalt efter at du har lavet denne opdatering. Der er ingen grund til at holde pause eller genstarte eksperimentet.Hvor ligger problemet i Google website optimizer scriptet?Scriptet i den gamle version anvender data som tegn, hvilket giver mulighed for at udf\u00f8re angreb og cross-site scripting p\u00e5 websites, der anvender scriptet, ved at inds\u00e6tte en ESCAPE kodning, tvinger man parseren(fortolkeren) til at anvende tegn som data, dette forhindrer adgang til websstedet via scriptet.Relaterede emner:Beskyt dit website mod indeksering p\u00e5 testdom\u00e6neFlytning af websiteGoogle.dk og deres serverops\u00e6tningA-B Splittest Google AdwordsKonverteringssporing"},{"@context":"https:\/\/schema.org\/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Google website optimizer sikkerhedsproblem","item":"https:\/\/blog.onlinemarketing.dk\/google-website-optimizer-sikkerhedsproblem.html#breadcrumbitem"}]}]