Advertisement
Promo

Security threats Toolkit

Google plugs Gmail security hole

Liam Tung ZDNet Australia

Published: 28 Sep 2007 12:23 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Three days after ethical hacker Petko Petkov announced his discovery of a cross-site scripting vulnerability in Gmail, Google says it has fixed the problem.

"We worked quickly to address the recently reported vulnerability, and we have rolled out a fix," a Google Australia spokesperson said today.

The vulnerability discovered by Petkov, who posted his findings at the GNUCitizen website, could potentially have allowed an attacker to seize control of session cookies if a user clicked on a malicious link while logged into their account.

Under the scenario, an attacker could siphon emails from the hacked account to a separate POP account, Chris Gatford, from penetration-testing company Pure Hacking, explained on Wednesday.

"If someone picks up on this before Google fixes it — or if someone knew of the vulnerability before this guy published it — this could be very damaging to Gmail users," Gatford said.

Read this

Feature
Q&A: Be alert to booby-trapped web pages

Trend Micro chief technology officer Raimund Genes warns that online life is about to get much hairier...

Read more +

However, Google's spokesperson said the search giant had not received any reports of the vulnerability being exploited, and added: "Google takes the security of our users' information very seriously."

Pure Hacking's Gatford said cross-site scripting vulnerabilities are gaining popularity amongst attackers and that many organisations are overlooking the problem.

"In the last year or so, [cross-site scripting vulnerabilities] have been used by attackers to grab cookie values and therefore gain access to normally password-protected sites," said Gatford.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
7 out of 7 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters