Google Community
Latest Forums Rules Resources
Custom Search

Go Back   Google Community > Google Forums > Gmail Forum

GoogleCommunity Sponsor

Reply
 
LinkBack Thread Tools Display Modes
Old 10-29-2004, 11:46 PM   #1 (permalink)
Master Googler
 
Join Date: Jul 2004
Posts: 514
Thanks: 0
Thanked 0 Times in 0 Posts
antioco2003
Security hole found in Gmail

So you’ve got a Gmail mail account? Or maybe you’ve just received an invitation? Well, we have some bad news for you: Your mail box is exposed. A major security hole in Google's mail service, allows full access to user accounts, without the need of a password.

"Everything could get publicly exposed – your received mails might be readable, as well as all of your sent mail, and furthermore – anyone could send and receive mail under your name", thus reveals Nir Goldshlagger, an Israeli hacker, on an exclusive interview with Nana NetLife Magazine. "Even more alarming", he explains, "is the fact that the hack itself is quite simple. All that is needed of the malicious hacker, beside knowledge of the specific technique, is quite basic computer knowledge, the victim's username – and that’s it, he's inside".

When approached, Google admitted to the security flaw. Google also assured us that this matter is being resolved, and that "the company will go to any length to protect its users".

The flaw which was discovered by Goldshlagger and was tested many times by Nana's editorial board had shown an alarming success rate. In order not to further jeopardize mail boxes' owners, we will only disclose that the process is based upon a security breach in the service's identity authentication. It allows the hacker to "snatch" the victims cookie file (a file planted in the victim's computer used to identify him) using a seemingly innocent link (which directs to Gmail's site itself). Once stolen, this cookie file allows the hacker to identify himself as the victim, without the need of a password. Even if the victim does change his password afterwards, it will be to no avail. "The system authenticates the hacker as the victim, using the stolen cookie file. Thus no password is involved in the authentication process. The victim can change his password as many times as he pleases, and it still won't stop the hacker from using his box", explains Goldshlagger.

Whether hackers have already used this method to compromise users' accounts is unclear at the moment.

Matters are several times worse when it comes to a service such as Gmail. Besides the obvious blow to Google's seemingly spotless image, we're looking here at a major threat to anyone who has turned to Gmail as his major email box. "Because Gmail offers a gigabyte of storage, several times bigger than most other web based mail services, users hardly delete any old correspondence", says Goldshlagger. "The result is a huge amount of mail accumulating in the users' boxes, which frequently include bank notices, passwords, private documents and other files the user wanted to backup. Who ever takes a hold of this data, could literally take over the victim's life and identity".

Ofer Elzam, a security expert for "Aladdin", who examined the security hole at Nana's Netlife request, explains: "This is a major threat, for the following reasons: First – the users have no way of protecting themselves. Second – it's quite easy to carry out, and third – it allows identity theft, which is nothing less than a serious danger to the victim".

"On the bright side", he adds, "its a good thing that this hole was found now, before the service was officially announced and offered to millions of users world-wide. I reckon it's just a matter of time before an automatic tool is made, which would allow even the less computer-savvy people to exploit this hack. The damage, needless to say, could be huge"

Is there a way, after all, to protect ourselves in the face of this danger? Elzam does not bear good news on the matter. "The only immediate solution that comes to mind is not using Gmail to store any messages or files that might be maliciously used. At least until Google attends to this problem"

Code:
http://net.nana.co.ilrticle/?ArticleID=155025&sid=10
antioco2003 is offline   Reply With Quote
 
Sponsored Links
Old 10-30-2004, 12:29 AM   #2 (permalink)
Google Guru
 
tokkolo's Avatar
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 2,022
Thanks: 0
Thanked 0 Times in 0 Posts
tokkolo is an unknown quantity at this point
Send a message via MSN to tokkolo
Jaiks!

I'm so glad that I don't have any important information in my gmail account. Anybody else but me can't do anything with the information I have in my inbox.

This is a serious security hole, especially if you store sencitive (sp?) information in your inbox!

Jaiks again!
__________________
A letter is like a flower
tokkolo is offline   Reply With Quote
Old 10-30-2004, 01:58 AM   #3 (permalink)
Noogle
 
Join Date: Oct 2004
Location: Germany
Posts: 18
Thanks: 0
Thanked 0 Times in 0 Posts
zirias
Send a message via ICQ to zirias Send a message via AIM to zirias Send a message via MSN to zirias
Full disclosure would be much better ...

But it just sounds like google made the same mistake that gmx made before: They don't derefer links. So it would be a good idea not to click on any links in emails received via gmail and only copy&paste links received from trustworthy persons. When I got that right, there is no risk for you when you never click on links in your emails.

Google should change it's code so that cookies also depend on the user's password and should rewrite links so that they point to another script, that cleans the environment (no referers, no cookies, ...) and then redirects to the original link.

Shocking thing that very similar mistakes are done again and again.

Greets, Felix
zirias is offline   Reply With Quote
Old 10-30-2004, 07:50 AM   #4 (permalink)
Master Googler
 
Join Date: Sep 2004
Location: United States
Posts: 967
Thanks: 2
Thanked 0 Times in 0 Posts
microdude431
Send a message via AIM to microdude431 Send a message via MSN to microdude431
glad i dont have any important info in my gmail account(s)
microdude431 is offline   Reply With Quote
Old 10-30-2004, 09:57 AM   #5 (permalink)
Elite Googler
 
Join Date: Jul 2004
Location: England
Posts: 1,573
Thanks: 0
Thanked 1 Time in 1 Post
broken
Send a message via MSN to broken
I hope they get that sorted soon. Luckily I don't have any important stuff in my mailbox.
broken is offline   Reply With Quote
Old 10-30-2004, 09:58 AM   #6 (permalink)
Master Googler
 
Join Date: Sep 2004
Location: United States
Posts: 967
Thanks: 2
Thanked 0 Times in 0 Posts
microdude431
Send a message via AIM to microdude431 Send a message via MSN to microdude431
maybe Google will give extra invites now!
microdude431 is offline   Reply With Quote
Old 10-30-2004, 11:37 AM   #7 (permalink)
Noogle
 
Join Date: Oct 2004
Location: Germany
Posts: 18
Thanks: 0
Thanked 0 Times in 0 Posts
zirias
Send a message via ICQ to zirias Send a message via AIM to zirias Send a message via MSN to zirias
It's irrelevant whether you think your mailbox is important or not. What really matters is: Have you ever clicked on links sent to your gmail-account? I think you're fine if not.

Greets, Felix
zirias is offline   Reply With Quote
Old 10-30-2004, 12:56 PM   #8 (permalink)
Noogle
 
Join Date: Sep 2004
Location: PPFFFFT! You'll need a location finding machine to know that!
Posts: 16
Thanks: 0
Thanked 0 Times in 0 Posts
nazgulking929
Send a message via AIM to nazgulking929
Quote:
Originally Posted by tokkolo
Jaiks!

I'm so glad that I don't have any important information in my gmail account.
Me too.
nazgulking929 is offline   Reply With Quote
Old 10-31-2004, 01:08 AM   #9 (permalink)
Noogle
 
Join Date: Oct 2004
Location: Germany
Posts: 18
Thanks: 0
Thanked 0 Times in 0 Posts
zirias
Send a message via ICQ to zirias Send a message via AIM to zirias Send a message via MSN to zirias
[1983-02-01] first "me, too" posting

really a milestone in usenet history

*scnr*, Felix
zirias is offline   Reply With Quote
Old 10-31-2004, 04:01 AM   #10 (permalink)
Master Googler
 
Join Date: Aug 2004
Location: Europe
Posts: 682
Thanks: 0
Thanked 0 Times in 0 Posts
Ashley
Yikes! I click links in my email! No offense to anyone who says they don't keep anything important in your mailboc; Antioco said that it allows hackers to send mail from your account too! They could get you in big trouble!
Ashley is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Similar Threads
Thread Thread Starter Forum Replies Last Post
Send gmail from webcam security software quintain Gmail Forum 1 07-22-2007 11:32 PM
BIGG GMAIL BUG FOUND digaomatias Gmail Forum 2 03-15-2006 07:17 PM
Security in GMAIL Gooooogler Gmail Forum 5 03-23-2005 03:39 AM
Google plugs hole exposing Gmail mail-boxes Jt0323 Gmail Forum 0 12-17-2004 07:42 PM
Security Flaws Found in XP SP2 claim.What? :( Orpheus Chit Chat 8 08-30-2004 10:53 PM


All times are GMT -8. The time now is 02:25 PM.


Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0
© 2004–2007 Google Community