« Previous Post
Next Post »

GMail Flaw Leaves Your Email Open To Anyone



Gmail LogoA new GMail exploit has been revealed that will essentially let malicious attackers keep tabs on the victim’s emails. The attack uses a cross-site request forgery (CSRF) to create a backdoor that can be used by an attacker to read the victim’s email.

Petko Petkov, of the PDF Exploit fame, has demonstrated the GMail bug for Zdnet to prove it works. The exploit does not require any user action, and unsuspecting users may already be victims.

The victim visits a page while being logged into GMail. Upon execution, the page performs a multipart/form-data POST to one of the GMail interfaces and injects a filter into the victim’s filter list. In the example above, the attacker writes a filter, which simply looks for emails with attachments and forward them to an email of their choice. This filter will automatically transfer all emails matching the rule. Keep in mind that future emails will be forwarded as well. The attack will remain present for as long as the victim has the filter within their filter list, even if the initial vulnerability, which was the cause of the injection, is fixed by Google.

Even if Google patches the flaw, affected users will still have to manually remove the filter to stop the attack.

For all of you using GMail, check your filters and make sure they’re all yours.

Technorati Tags: ,

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Netvouz
  • DZone
  • ThisNext
  • MisterWong
  • NewsVine
  • Slashdot
  • StumbleUpon
  • Furl
  • Fark
  • Wists
  • Technorati
  • Reddit
  • SphereIt
  • Bumpzee
  • Netscape
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...



Thank you for reading this post. You can now Read Comments (24) or Leave A Trackback.

24 Responses to “GMail Flaw Leaves Your Email Open To Anyone


Subscribe without commenting


Leave a Reply


Note: Any comments are permitted only because the site owner is letting you post, and any comments will be removed for any reason at the absolute discretion of the site owner.


This blog uses the CommentLuv plugin which will try and parse your sites feed and display a link to your last post, please be patient while it tries to find it for you. A link to the plugin can be found in the sidebar under Featured Sites.