ZonaNet Blog: Gmail's Zero-Day Flaw Allows Attackers to Steal Messages
ZonaNet Blog Home Page

MAIN MENU
SEARCH
BLOGGER

Google

POLL
Are You ZonaNet Blog Visitor?
Always
Sometimes
Never

     



eXTReMe Tracker

 
Gmail's Zero-Day Flaw Allows Attackers to Steal Messages
Monday, October 01, 2007
Accounts on Google Inc.'s Gmail can be easily hacked, allowing any past -- and future e-mail messages -- to be forwarded to the attacker's own in-box, a vulnerability researcher said Tuesday.

Dubbed a "cross-site request forgery" (CSRF), the Gmail bug was disclosed Tuesday by Petko Petkov, a U.K.-based Web vulnerability penetration tester who has made a name for himself of late. In the past two weeks, Petkov has publicly posted information about critical, zero-day bugs in Apple Inc.'s QuickTime, Microsoft Corp.'s Windows Media Player and Adobe Systems Inc.'s Portable Document Format (PDF).

According to Petkov, who declined to release details about the vulnerability, attackers can use Gmail's filtering feature to exploit the bug. An attack, he said, would start with a victim visiting a malicious Web site while also still logged into his Gmail account. The malicious site would then perform what Petkov called a "multipart/form-date POST" -- an HTML command that can be used to upload files -- to one of the Gmail application programming interfaces, then inject a rogue filter into the user's filter list.

thanks...ZonaNet

Labels:

posted by ZonaNet @ 4:55 PM  
0Comments:
Post a Comment
Home
 
About Me

Name: Yazin Alhamdi
Country: LIBYA
About Me: Angel!
Email: yazin.alhamdi@gmail.com
My Guest Book
Previous Post
Archives
Links
Powered by

BLOGGER

© ZonaNet Blog Template by ZonaNet