Google plugs Gmail security hole

  • Email a Friend
  • Print Page
Google plugs Gmail security hole
By Shaun Nichols
Oct 2, 2007 7:19 AM
Tags: Google | plugs | Gmail | security | hole

Google has patched a recently reported Gmail flaw that could allow attackers to steal information from inside a user account.

The vulnerability was discovered by independent security researcher Petko Petkov, who classified it as a cross-site request forgery.

The attack is triggered when a user visits a website containing malicious code while logged into Gmail. The code executes a special command to access the Gmail account and sets up a new filter without the user's knowledge.

An attacker could configure the filter to forward any archived or future messages with certain keywords or senders' names to another email account.

Petkov did not release any details about the attack until Google had issued a fix.

The researcher argued that the attack could be more dangerous than system-based malware because a filter could be used to pick out precise personal details, such as bank account information.

"In an age when all the data is in the cloud, it makes no sense for the attackers to go after your box," Petkov wrote. "It is a lot simpler to install one of these persistent backdoor/spyware filters."

A Google spokesperson confirmed the vulnerability to www.vnunet.com but stressed that no attacks had been reported.

Users looking to verify that their Gmail accounts are still secure can check their active email filters by clicking on the 'Filters' tab in Gmail's 'Settings' panel.

Copyright © 2009 vnunet.com


 
Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
Top Stories
Conroy opens NBNCo regulation debate
Part two of the regulatory reforms paper.
 
Utilities wise up to smart grids
Power to the people?
 
Sydney Water turned off wrong pipe
Admits error with Macquarie Telecom data centre.
 
Exclusive Data Centre - Sponsored Content by Microsoft

Latest Comments

"I turn bluetooth off on my mobile to save the battery. Looks like now I've got another reason. "
by Slatts Jul 4, 2009 1:09 PM
 
"I'm kind of assuming that the water was used in water cooled condensers for the air-conditioning...."
by Slatts Jul 2, 2009 8:54 PM
 
"Why do we have to listen to Nick Minchin's comments? He is just about irrelevant in his opinions ..."
by ngo Jul 2, 2009 8:35 PM
 
" It's not very surprising that the Chinese junta still wants to impose the 'Green Dam - Youth ..."
by anonymous Jul 2, 2009 3:49 PM
 
"I would suggest for anyone wanting to join in the BOINC projects such as SETI@home, World ..."
by wolfgang8741 Jul 2, 2009 5:37 AM

Polls

What will you do when your iPhone contract comes up for renewal?




   |   View results
Retain my current service provider
  12%
 
Switch to a cheaper plan
  18%
 
Switch to a better network
  17%
 
Switch to whoever offers free tethering
  18%
 
Change handset altogether
  35%
TOTAL VOTES: 196

Vote