Windows Support Tools

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, 23 November 2008

Gmail exploit may allow attackers to forward e-mail

Posted on 23:09 by Unknown

A Gmail security vulnerability may allow an attacker to set up filters on users' e-mail accounts without their knowledge, according to a proof of concept posted Sunday at GeekCondition.com.

In his post, Brandon writes that the vulnerability has caused some people to lose their domain names registered through GoDaddy.com.

Without posting the full exploit, here is the key as Brandon explains it relies on obtaining the variables that represent the user name and "at":

When you create a filter in your Gmail account, a request is sent to Google's servers to be processed. The request is made in the form of a url with many variables. For security reasons, your browser doesn't display all the variable contained within the url. Using FireFox and a plugin called Live HTTP Headers, you can see exactly what variables are sent from your browser to Google's servers.

After that, an attacker just needs to identify the variable that is the equivalent of the username.

"Obtaining this variable is tricky but possible," he writes. "I'm not going to tell you how to do it, if you search hard enough online you'll find out how."

The "at" variable can be obtained by visiting a malicious Web site, writes Brandon, who suggests that Google make the "at" variable expire after every request rather than after every session.

To avoid being a victim of the vulnerability, users should check their filters often, Brandon suggests. Firefox users can download an extension called NoScript that helps prevent these attacks, he said.

Of course, any Web site that uses cookies for authentication requests can be taken advantage of in the same way. To avoid becoming a victim to this type of exploit, Gmail users should logout of their accounts when they are not in use, and--of course--not visit Web sites that they don't trust.

Google representatives did not immediately return a request for comment
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • What is Cloud Computing ?
  • Setting up a DHCP server in Windows 2003
    The DHCP server assigns a client an IP address taken from a predefined scope for a given amount of time. If an IP address is required for lo...
  • Cartoons of the Week
  • Manage your home network better with Network Magic 5.0
    Cisco announced on Thursday Network Magic 5.0, a suite of network management software. This is is the first product released by Cisco since ...
  • Google Sinks Cash into Undersea Cable
    Google has joined the Unity consortium, which will build a $300 million fiber optic cable linking the US and Japan. The 7.68 Tbps, 10,000 ki...
  • Battle Progress Map
  • Exchange Server 2010 Beta available
    Microsoft Exchange Server 2010 brings a new and rich set of technologies, features, and services to the Exchange Server product line. This t...
  • Nambara Sanda Wage
  • Complete Wireless Design (McGraw-Hill, 2008, English)
    ON THE CD-ROM *PUFF RF/Microwave circuit simulation software *Sonnet Lite electromagnetic simulation software *National's PLL Design Pro...
  • Keyshia Cole - Just Like You (2007)
    1- Let It Go feat Missy Elliot and Lil Kim [03:58] 02- Didn't I Tell You feat Too Short [03:52] 03- Fallin Out [04:27] 04- Give Me More ...

Categories

  • ISA Firewall
  • ISA Server 2006
  • Quick Tips
  • Reports
  • Tips

Blog Archive

  • ►  2013 (7)
    • ►  October (6)
    • ►  February (1)
  • ►  2012 (10)
    • ►  September (3)
    • ►  August (3)
    • ►  July (3)
    • ►  June (1)
  • ►  2011 (16)
    • ►  August (2)
    • ►  July (4)
    • ►  June (3)
    • ►  May (1)
    • ►  April (1)
    • ►  March (4)
    • ►  January (1)
  • ►  2010 (12)
    • ►  December (3)
    • ►  October (4)
    • ►  March (1)
    • ►  January (4)
  • ►  2009 (67)
    • ►  August (2)
    • ►  July (18)
    • ►  June (23)
    • ►  April (3)
    • ►  March (6)
    • ►  February (7)
    • ►  January (8)
  • ▼  2008 (319)
    • ►  December (30)
    • ▼  November (43)
      • Indian politicians must mind their own business an...
      • HTC expecting to ship 1 million G1s by the end of ...
      • Verizon Omnia announced, coming December 8th
      • Story or no story, the Verizon BlackBerry Storm OS...
      • The BlackBerry Storm has issues - at least six of ...
      • 2007 Year-End Zeitgeist
      • Google Drops Truth Bomb over iPhone API
      • Amazon Fulfillment Web Service (Amazon FWS)
      • Amazon Takes the Humans Out of Fulfillment With Ne...
      • How Telnic Will Revolutionize Dialing
      • Dozens of People Killed in Mumbai Attacks
      • Exchange 2003 Message Tracking and Logging
      • How to enable message tracking in Exchange 2000 Se...
      • A Free Social Utility for Your Time-Based Life
      • Exchange Server Archiver Beta - available now
      • FlashLynx Video Download Software - Free
      • 53+ Great Web 2.0 Feeds
      • Google Health Has Arrived
      • Where does your time go?
      • Defend against web-based threats and block undesir...
      • FREE 1 Year BitDefender Antivirus 2009 Genuine Lic...
      • FREE ESET NOD32 Antivirus v2.7/3.0/4.0 Username an...
      • Microsoft to offer free security
      • Cheers were heard across the Internet earlier toda...
      • Microsoft To Rebrand Search. Will It Be Kumo?
      • Gmail exploit may allow attackers to forward e-mail
      • Samsung launches 256GB solid-state drive
      • Chat everywhere! With our eBuddy Mobile Messenger ...
      • Visualizing Facebook from outer space
      • Swedish carrier planning iPhone MMS app
      • Punareen under LIONS control
      • Featured Freeware: gMote
      • Featured Freeware: Stellarium
      • 5 Reasons Obama Is Good For Geeks
      • Father of iPod Quits Apple, Replaced By Godfather ...
      • motorola good mobile launched in sri lanka with Ri...
      • CISCO CCNA 4.0 Exploration and Discovery
      • SMS Free Sender 2.6.8
      • VoxOx is an entirely new way to take complete cont...
      • Featured Freeware: Wrapper
      • Documents To Go Premium now on BlackBerry
      • Trillian is a fully featured, stand-alone, skinnab...
      • Configuring ActiveSync on a Windows Mobile 5.0 Sma...
    • ►  October (45)
    • ►  September (12)
    • ►  August (18)
    • ►  July (27)
    • ►  June (15)
    • ►  May (7)
    • ►  April (55)
    • ►  March (65)
    • ►  January (2)
  • ►  2007 (10)
    • ►  December (2)
    • ►  November (8)
Powered by Blogger.

About Me

Unknown
View my complete profile