Posted by Steven Musil
A Gmail security vulnerability may allow an attacker to set up filters on users' e-mail accounts without their knowledge, according to a proof of concept posted Sunday at the blog Geek Condition.
In a post, Geek Condition's "Brandon" writes that the vulnerability has caused some people to lose their domain names registered through GoDaddy.com.
Without posting the full exploit, Brandon explains that it relies on obtaining the variables that represent the username and "at":
When you create a filter in your Gmail account, a request is sent to Google's servers to be processed. The request is made in the form of a url with many variables.
For security reasons, your browser doesn't display all the variables contained within the URL. Using Firefox and a plug-in called Live HTTP Headers, you can see exactly what variables are sent from your browser to Google's servers.
After that, an attacker just needs to identify the variable that is the equivalent of the username.
"Obtaining this variable is tricky but possible," he writes. "I'm not going to tell you how to do it; if you search hard enough online, you'll find out how."
The "at" variable can be obtained by visiting a malicious Web site, writes Brandon, who suggests that Google make the "at" variable expire after every request rather than after every session.
To avoid being a victim of the vulnerability, users should check their filters often, Brandon suggests. Firefox users can download an extension called NoScript that helps prevent these attacks, he said.
Of course, any Web site that uses cookies for authentication requests can be taken advantage of in the same way. To avoid becoming a victim to this type of exploit, Gmail users should log out of their accounts when they are not in use, and--of course--not visit Web sites they don't trust.
A Google representative said the company was trying to contact Brandon for specifics on his proof of concept.
Categories
- academic | technological (5)
- commerce | finance (19)
- education | language (11)
- electronic | digital (4)
- health | diet (28)
- industry | giant (11)
- network | website (12)
- product | application (14)
Sponsored Links
Blog Archive
-
▼
2008
(90)
-
▼
December
(90)
- Using POP Displays to Enhance Your Sales
- Choosing the Right Direct Mail Product For Your Ho...
- Networking Gold Diggers
- Secrets to Small Business Success - Network Your B...
- How to Get Lean Muscle - 3 Ways to Force a Skinny ...
- Why Skinny Guys Always Struggle to Build Muscle
- Tips on Creating a Controversial Press Release
- How to Personalise an Engraved Executive Gift
- Low Budget PP - Why Pay Them When You Can Do it Yo...
- Warning - The Following 9 Points May Turn You Into...
- Basics and Benefits of Yoga
- what is yoga?
- Hatha Yoga For Good Health
- How to Choose the Perfect Yoga Class For Your Type
- Top Yoga Cures For Winter Blues
- Hearing Loss - Causes and Symptoms You Should Know
- Ear Pain and the Best Means For Treatment
- Stop Mumbling!
- Popular Special Effects Lenses
- What is the Difference Between Monthly Contacts an...
- Apple files Swipe Gestures patent for iPhone keyboard
- NASA Awards Cargo Contracts
- Post-holiday sales bring in shoppers, but they may...
- What's to Love About a Lima Bean?
- The Right Supplements for Alzheimer's
- Here's Ya'll Lima Bean Recipes
- Papaya As a Healing Food
- Papaya Relish Recipe
- Treatment for Stage 1 Invasive Breast Cancer: Frui...
- Healthy, Tasty, American Treat
- Make Christmas different and healthy this year
- More tips for lite Christmas cakes
- Tips for making healthy Christmas cakes
- Google Expands Parked Domain Ads Program
- Twitter Humiliates MySpace
- A Boon for Xoopit and Other Productivity Add-Ons
- The Extraordinary Happenings At BitTorrent
- OpenX Shows Growth, Ramps Up Revenue Streams
- Oxite - Microsofts Open Source Blogging Platform
- Watch Out WiFi, Here Comes MiFi
- Who will Preserve Your Digital Data?
- Extracting Images From the Brain
- Google Chrome Out Of Beta
- 'Report a Concern' at Google Maps
- Google Releases Browser Security Handbook
- Send SMS in Gmail Chat
- Change.gov Using Google Moderator
- Polygons Evolving Into Your Custom Picture
- Yahoo Laying Off Employees and Providing Layoff Ta...
- Google Street View US Expands
- Google Book Search Adds Magazines
- Read Wikipedia on Mobile Phones through Email
- Visual Guide to Time Around the World
- Access del.icio.us Bookmarks on your Mobile Phone
- Most Popular Google Subdomains
- How I Make Money Blogging
- Choosing a Blog Platform
- What is a Blog?
- How Bloggers Make Money from Blogs
- How to Write Your “About Me” Page
- N97-Nokia Strikes Back iPhone-Apple
- Parsnip Gnocchi-Recipe
- Rucola Cashew Pesto-Recipe
- Why Does Google Allow Ads for AdSense Ready Websites?
- AdSense Click Fraud in India - How The Whole Syste...
- Technorati Ad Network for Blogs is Live
- BlogAds Invitations Available for Bloggers & Site ...
- Learn How To Pronounce Foreign Names Correctly
- Online networks a magnet for job-seekers
- Gmail 'vulnerability' turns out to be phishing scam
- 'Minority Report' Computer Interface Becomes Reality
- Spanish Dessert Recipes - Flan
- Best Spanish Rice Recipe
- Black rice with squid
- Gmail exploit may allow attackers to forward e-mail
- How to Access Blocked Websites, Unblock Restricted...
- Top 5 Worst Things About The iPhone
- NetVet and the Electronic Zoo History
- 11 Tips to Improve Your Landing Page
- Some Free eBook Websites
- Sacred Texts & Religion
- Individual Topics/Miscellaneous
- World - Other Languages,Regional and National
- Free audio books
- Other Free Books in English
- Other Free Australian Books
- Best free Digital Libraries - World
- Best free Digital Libraries - NZ
- Best free Digital Libraries - Australia
- Government working on Citigroup rescue
-
▼
December
(90)
Tuesday, December 2, 2008
Gmail exploit may allow attackers to forward e-mail
Posted by egfner at 9:42 PM
Labels: product | application
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment