On mySimon: Classic V-Neck Cardigans for Fall
BNET Business Network:
BNET
TechRepublic
ZDNet

August 5th, 2007

Gmail vulnerability disclosed at Defcon

Posted by Garett Rogers @ 3:40 pm

Categories: Gmail

Tags: Google Gmail, Network, Vulnerability, E-mail, Garett Rogers

Though it’s not specific to Gmail, or easily exploitable by users outside your network, a session hijacking demonstration by Robert Graham showed hackers how to take over a users email account by simply sniffing network traffic and stealing cookies. In the demonstration, George Ou volunteered an email address he created to be hacked into — and it didn’t take long. Within seconds, the attacker was able to use a point-and-click interface to get access to this account and send a message from it.

The demonstration highlights how easy unsecure network traffic can make for some very simple session hijacking. One way you can avoid having your Gmail account taken over by people on your network is to use the SSL version — be warned though, any website that relies heavily on cookies for authentication remains vulnerable.

If you don’t have Greasemonkey installed, or you still use Internet Explorer, get used to typing “https://www.gmail.com” to check your email — doing this will safeguard yourself from prying eyes through network sniffing. If you have Firefox, you can install this Greasemonkey script to ensure your session always remains in “secure mode”.

Garett RogersGarett Rogers is employed as a programmer for iQmetrix, which specializes in retail management software for the wireless industry. See his full profile and disclosure of his industry affiliations.


Email Garett Rogers

Subscribe to Googling Google via Email alerts or RSS.

  • Talkback
  • Most Recent of 6 Talkback(s)
set SSL always on
You can also use the Add-on "CustomizeGoogle" which gives you lots of options to customize Google to your liking.... (Read the rest)
Posted by: CzarCar Posted on: 08/10/07 You are currently: a Guest | | Terms of Use
Google Security  paulloke | 08/05/07
How can I set SSL "always on" in Gmail?  pjotr123 | 08/06/07
Start by reading the article - it told you how!  CobraA1 | 08/06/07
set SSL always on  CzarCar | 08/10/07
Can be prevented by a good Web App Firewall  guyr@... | 08/06/07
This has ZERO to do with application firewalls  georgeou | 08/06/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here