Serious cross-site request forgery vulnerability found in Gmail
Category internet, Tips & Tricks, hitnews | Permalink | 29. September 2007
« Ubuntu New music player - Exaile | Youtube Video Wooden Mirror by DANIEL ROZIN »
Source : arstechnica.com
Security researcher Petko Petkov has revealed a cross-site request forgery vulnerability in Gmail that makes it possible for a malicious web site to surreptitiously add a filter to a user’s Gmail account that forwards e-mail to a third-party address. Petkov’s proof-of-concept exploit for this vulnerability, which has been independently verified but not publicly released, uses a multipart/form-data POST to send instructions to Gmail’s internal API. The vulnerability can only be exploited when the user is currently logged in to the Gmail service.
This is the second major Google security vulnerability to be revealed this week. On Monday, security researcher Fernando Bedford provided a proof-of-concept exploit for a Google cross-site scripting vulnerability in Google’s Blogspot polls API that facilitated e-mail hijacking and address book sniffing. That vulnerability was fixed by Google shortly after it was reported, but it is presently unclear whether or not the vulnerability discovered by Petkov has been fixed yet.
Source and More : arstechnica.com
,
Related Posts
- Gmail Paper next year Everyone loves Gmail. But not everyone loves email, or the digital era. What ever happened to stamps...
- GMail Drive 1.0.11 Beta GMail Drive is a Shell Namespace Extension that creates a virtual filesystem around your Google Gma...
- Gmail for your mobile device Google announced that now gmail is available as an app for your mobile phone. I downloaded this toda...
- How to Gmail Works on the iPhone Another way to use Gmail on your iPhone is through the browser. By going to m.gmail.com you get ...
- Youtube Gmail: A Behind the Scenes Video We asked you to help us imagine how an email message travels around the world. All it took was a vid...
- Google invites everyone to Mail Search firm opens up email service to EMEA. Google has dropped the invitation-only system for its...
- Gmail Theater: Why Use Gmail with Youtube Video [youtube]http://www.youtube.com/watch?v=uBbmiQhuAhU[/youtube]...
- AJAX Alternatives? Gmail Choice! Every now and then, I keep hearing people discussing the power of AJAX. First, let me explain in bri...
- Ubuntu CheckGmail 1.11 One loss you'll experience in the migration from PC to Ubuntu is the use of your Gmail notifier....
- Gmail Paper next year "Everyone loves Gmail. But not everyone loves email, or the digital era. What ever happened to stamp...


































































