Google Gmail E-mail Hijack

Google Gmail E-mail Hijack

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Google Gmail E-mail Hijack MowGreen [MVP] 09-26-2007
Posted by MowGreen [MVP] on September 26, 2007, 3:37 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/

While being logged into Gmail with the brower interface, IF one opens
another tab/browser window and stumbles across an 'evil' site, the
'evil' site can inject a filter into the Filter List. The attacker can
then forward emails wherever they want via the filter.
The above site contains graphics that show how this is accomplished.

> The attack will remain present for as long as the victim has the filter within
their
> filter list, even if the initial vulnerability, which was the cause of the
injection, is
> fixed by Google.


Bullseye on Google: Hackers expose holes in GMail, Blogspot, Search
Appliance
http://blogs.zdnet.com/security/?p=539

> The unpatched GMail bug, which was demonstrated for me by hacker Petko D.
Petkov, is
> particularly nasty because of the way the exploit works without any user
action and the
> fact that it’s difficult for the average GMail user to know that e-mails are
being stolen.



MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============

Posted by jen on September 27, 2007, 12:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/
> While being logged into Gmail with the brower interface, IF one opens
> another tab/browser window and stumbles across an 'evil' site, the
> 'evil' site can inject a filter into the Filter List. The attacker can
> then forward emails wherever they want via the filter.
> The above site contains graphics that show how this is accomplished.
>> The attack will remain present for as long as the victim has the
>> filter within their filter list, even if the initial vulnerability,
>> which was the cause of the injection, is fixed by Google.
> Bullseye on Google: Hackers expose holes in GMail, Blogspot, Search
> Appliance
> http://blogs.zdnet.com/security/?p=539
>> The unpatched GMail bug, which was demonstrated for me by hacker
>> Petko D. Petkov, is particularly nasty because of the way the exploit
>> works without any user action and the fact that it’s difficult for
>> the average GMail user to know that e-mails are being stolen.

Simple remedy... Use Firefox with No-Script:
GMail POST Mortem, CSRF Countermeasures and NoScript Misconceptions:
http://hackademix.net/2007/09/26/gmail_csrf/

-jen



Posted by Mark Randall on October 1, 2007, 3:05 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> Simple remedy... Use Firefox with No-Script:
> GMail POST Mortem, CSRF Countermeasures and NoScript Misconceptions:
> http://hackademix.net/2007/09/26/gmail_csrf/

In other news, people who do not breathe are less likely to catch airborne
disease.

--
Mark Randall
http://www.awportals.com


Similar ThreadsPosted
FBI can install a piece of spyware called "cipav" through gmail... July 20, 2007, 10:37 am
posting log of Hijack This December 31, 2005, 6:19 pm
Computer Hijack June 28, 2006, 3:41 am
Browser Hijack? February 21, 2007, 9:10 am
Download.Trojan (aka Desktop HiJack) April 25, 2006, 11:13 pm
MS Outlook automatically change email pop server email January 14, 2006, 9:13 pm
Uploading an email from email client to web based host September 22, 2006, 9:46 am
Re: Forum software email security: email obfuscation October 14, 2006, 12:46 pm
Browser hijack attempt resulting in lost favorites (= no bookmarks) October 11, 2005, 8:51 pm
New Google Toolbar August 10, 2006, 10:50 am

The site map in XML format XML site map

Contact Us | Privacy Policy