Google working to patch Gmail message-forwarding flaw

Powered by SC Magazine
 

A flaw in Gmail can allow an attacker to forward all messages with attachments to another email address.

An attacker must force a potential victim, logged into their Gmail account, to visit a malicious page that injects a filter into the victim's filter list, according to researcher Petko Petkov of Gnucitizen. The filter sends emails with attachments to an address of the attacker's choice.

Classifying exploitation a cross-site request forgery, Petkov warned that even if Google releases a fix for the flaw, messages would still be forwarded to the third-party address because the filter is still present.

Petkov on Tuesday urged other researchers not to disclose details of the flaw until Google fixes it, saying the vulnerability is “extremely nasty if you ask me” on the Gnucitizen blog.

“If you find this vulnerability, please do not disclose it. Let Google fix it first and then blog about it,” he said. “In an age where all the data is in the cloud, it makes no sense for the attackers to go after your box. It is a lot simpler to install one of these persistent backdoor/spyware filters. Game over! They don't own your box, but they have you, which is a lot better.”

Petkov told SCMagazineUS.com today that Google replied to him, saying that they have “confirmed the vulnerability and now they are looking for ways to fix it.”

Google today released a statement saying that the company would issue a fix shortly.

“Google takes the security of our users' information very seriously, and we are working on a fix to the recently reported vulnerability, which we expect to be implemented shortly,” the Mountain View, Calif.-based search giant said in a statement.

Petkov this month also discovered a flaw in QuickTime and Firefox, and a vulnerability in Adobe Reader – both fixed by vendors last week.

See original article on SC Magazine US

Copyright © SC Magazine, US edition


Google working to patch Gmail message-forwarding flaw
 
 
 
Top Stories
Myer CIO named retailer's new chief executive
Richard Umbers to lead data-driven retail strategy.
 
Empty terminals and mountains of data
Qantas CIO Luc Hennekens says no-one is safe from digital disruption.
 
BoQ takes $10m hit on Salesforce CRM
Regulatory hurdles end cloud pilot.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  35%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 4121

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 1403

Vote