Results 1 to 2 of 2

Thread: How your Gmail can get hacked

  1. #1
    Join Date
    Oct 2008
    Posts
    71

    How your Gmail can get hacked

    All those Gmail fans out there, here's an important piece of security news for you. A blogger, Brandon Partridge, on Geek Condition has reported that a security vulnerability in Gmail may allow an attacker to hack into Gmail users accounts.

    What exactly it is

    According to the blog, the security vulnerability may allow an attacker to set up filters on users' email accounts without their knowledge.

    Web developer Partridge warned that an attacker can force unsuspecting Gmail users to create malicious message filter without their knowledge.

    Through this, the attacker can hijack messages sent to the victim's Gmail account by redirecting specific messages into the trash and forwarding a copy to the attacker, or so Partridge claims.

    Victim can lose his domain

    In the post on Geek Condition Brandon writes that the vulnerability has caused many people to lose their domain names registered through GoDaddy.com. GoDaddy is one of the largest domain name registrar and is the flagship company of The Go Daddy Group Inc.

    The security flaw in Gmail allows a hacker to forward GoDaddy account reset information by the victim without his/her knowledge or consent. This is done by creating a filter that forwards GoDaddy's `change of password' mail to the hacker and deletes it from users' inbox.

    How hacker creates filters

    Wondering is it possible to create a malicious filter without having access to a user's Gmail username and password? No, it is not. However, hackers can force users to create the filter without their knowledge.

    When a user creates a filter in Gmail account, a request is sent to Google servers to get it cleared. The request is in form of a URL with many variables that the browser doesn't display. However, web browser FireFox and a plugin called Live HTTP Headers, displays exactly what variables are sent to Google servers.

    Through a process of elimination, the role of each variable can be ascertained. A particular variable is equivalent to the username which is permanent. Other variable can be determined by tricking the user to visit a web page that has a malicious code. This malicious code steals the cookie from the user and creates an iframe with a URL containing the variables that authorise Gmail to create filter for the user's account.

    Source : infotech.indiatimes

  2. #2
    Join Date
    Oct 2008
    Posts
    71

    Re: How your Gmail can get hacked

    How can you prevent it

    In order to prevent hackers to exploit this loophole, frequently monitor your filters. In case you find something suspicious, report it immediately.

    Firefox users can download an extension called NoScript that helps prevent such hacks, suggests Brandon. And always remember being cautious can help you save from many such attacks.

    Also, to avoid becoming a victim to such attacks, Gmail users should log out of their accounts when they are not in use, as well as avoid visiting websites you don't trust.

    How Google can help

    To avoid such vulnerabilities, Brandon says that Google needs to device a mechanism which makes variables or session authorisation Key expire after each request than expiring after each session.

    Meanwhile, a Google spokesperson reportedly told media that the company was trying to contact Brandon for specifics on his proof of concept.

    The company representative said that Google is trying to reach the blogger making this claim for more details, but we haven't seen evidence that this would be specific to Gmail.

Similar Threads

  1. Gmail Account Hacked in Hathway
    By Kungfu Pandey in forum India BroadBand
    Replies: 9
    Last Post: 21-12-2011, 08:54 PM
  2. Gmail hacked from HTC EVO
    By DaminiAMD in forum Portable Devices
    Replies: 5
    Last Post: 02-07-2011, 12:32 AM
  3. Facebook and Gmail account id is hacked
    By shibinpanayi in forum Networking & Security
    Replies: 1
    Last Post: 03-06-2011, 02:33 AM
  4. How to know if someone has hacked Gmail account and how to recover
    By mADiRAkSHii in forum Technology & Internet
    Replies: 3
    Last Post: 18-01-2011, 11:46 AM
  5. Gmail account hacked
    By Elsie in forum Technology & Internet
    Replies: 3
    Last Post: 22-10-2008, 07:25 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,714,048,531.51090 seconds with 17 queries