keyongtech


  keyongtech > security

 #1  
09-26-07, 08:37 PM
MowGreen [MVP]
http://www.gnucitizen.org/blog/googl...ack-technique/

While being logged into Gmail with the brower interface, IF one opens
another tab/browser window and stumbles across an 'evil' site, the
'evil' site can inject a filter into the Filter List. The attacker can
then forward emails wherever they want via the filter.
The above site contains graphics that show how this is accomplished.

> The attack will remain present for as long as the victim has the filter within their
> filter list, even if the initial vulnerability, which was the cause of the injection, is
> fixed by Google.



Bullseye on Google: Hackers expose holes in GMail, Blogspot, Search
Appliance
http://blogs.zdnet.com/security/?p=539

> The unpatched GMail bug, which was demonstrated for me by hacker Petko D. Petkov, is
> particularly nasty because of the way the exploit works without any user action and the
> fact that it’s difficult for the average GMail user to know that e-mails are being stolen.




MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============
 #2  
09-27-07, 05:32 PM
jen
"MowGreen [MVP]" <mowgreen> wrote in message
news:3848
> [..]
> While being logged into Gmail with the brower interface, IF one opens
> another tab/browser window and stumbles across an 'evil' site, the
> 'evil' site can inject a filter into the Filter List. The attacker can
> then forward emails wherever they want via the filter.
> The above site contains graphics that show how this is accomplished.
> Bullseye on Google: Hackers expose holes in GMail, Blogspot, Search
> Appliance
> [..]


Simple remedy... Use Firefox with No-Script:
GMail POST Mortem, CSRF Countermeasures and NoScript Misconceptions:
http://hackademix.net/2007/09/26/gmail_csrf/

-jen
 #3  
10-01-07, 08:05 PM
Mark Randall
"jen" <jen> wrote:
> Simple remedy... Use Firefox with No-Script:
> GMail POST Mortem, CSRF Countermeasures and NoScript Misconceptions:
> [..]


In other news, people who do not breathe are less likely to catch airborne
disease.
Similar Threads
Thread Thread Starter
Anyone care to buy a 'Google Stack'? e-mail me: marty.musatov@gmail.com:/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/

mII7nAtZ61iJz1gJA2lnUvh05l58hk_8EGD-weBX7JfnSgBZH s4quB766b-pbEBioZAVZG4WLBfGm6ze2qzKD77HBk_8VCGXDJ 0nRqzezdC0fr0Wu0QnKxUiwbkafPvDt6bvCuVPYWnbMvoZEsD hxH-aANUGt-Aan6T53bgHUJba...

1 &gt; I Am
how do I add gmail (google e-mail) to office outlook.

I found information and seem to have successfully lnked up with my yahoo mail, but can't find info to do the same for my gmail acct.

Bruce
Sent To Configure to use with webmail Google Mail (gmail) Account

Hi, I use WinXP Prof. Using Google Mail alias Gmail (Web-Based E-Mail). I would like to use the "send to" function, in order to easily send files via the internet. I would...

Daniel Berlin
Gmail, Google calendar and Windows live mail

Recently obtained a gmail account (wanted to test IE 7.0 with Gmail) Clean system, Zone Alarm Pro 6.1.7, Panda Antivirus, system specs already posted several...

Old Beta Tester
Sent To Configure to use with webmail Google Mail (gmail) Account

Hi, I use WinXP Prof. Using Google Mail alias Gmail. I would like to use the "send to" function, in order to easily send files via the internet. I do not know how to...

Daniel Berlin

Privacy Policy | All times are GMT. The time now is 12:17 AM.

Merging Information Logo
[Deutschland] [España] [France] [Italia] [Nederland] [Polska] [United Kingdom]