Google plugs Gmail security hole

 

Google has patched a recently reported Gmail flaw that could allow attackers to steal information from inside a user account.

The vulnerability was discovered by independent security researcher Petko Petkov, who classified it as a cross-site request forgery.

The attack is triggered when a user visits a website containing malicious code while logged into Gmail. The code executes a special command to access the Gmail account and sets up a new filter without the user's knowledge.

An attacker could configure the filter to forward any archived or future messages with certain keywords or senders' names to another email account.

Petkov did not release any details about the attack until Google had issued a fix.

The researcher argued that the attack could be more dangerous than system-based malware because a filter could be used to pick out precise personal details, such as bank account information.

"In an age when all the data is in the cloud, it makes no sense for the attackers to go after your box," Petkov wrote. "It is a lot simpler to install one of these persistent backdoor/spyware filters."

A Google spokesperson confirmed the vulnerability to www.vnunet.com but stressed that no attacks had been reported.

Users looking to verify that their Gmail accounts are still secure can check their active email filters by clicking on the 'Filters' tab in Gmail's 'Settings' panel.

Copyright ©v3.co.uk


Google plugs Gmail security hole
 
 
 
 
 
Top Stories
Telstra shifts BigPond email to Windows Live
All data to be migrated to Microsoft cloud.
 
Windows 8: Under the hood
Part One of iTnews' enterprise guide to Windows 8.
 
iTnews on tour: The Executive Summit Series
Join us in Sydney and Melbourne to meet Australia's tech leaders.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Would you be concerned about your business' email data being hosted offshore?

   |   View results
Yes
  89%
 
No
  11%
TOTAL VOTES: 90

Vote