Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

ADVISORIES

Gmail, eBay, MySpace – STILL Vulnerable

- Web 2.0 insecure as hell

By: Alexandru Dumitru, Security News Editor

Gmail, eBay, MySpace, banking sites, social network sites, any site, you just name it…they're all vulnerable. You can get your data phished in a second. It doesn't matter if you have a firewall and an anti-virus; if a hacker really wants to get your data, he will. But that's not the news; it may have been news about a month ago, but the thing is that not even the web
giants mentioned in the title fixed the bugs.

Now, let me tell you how this goes: if one hacker uses a plain-vanilla network sniffer to "read" the cookies (I know this sounds stupid, but it's techie tongue) you get from Hotmail for instance he can use them to log in with your data. Of course, I just gave an example, there are plenty more cases in which this works. If you get cookies from a site, then you can be cloned. And this even works with HTTPS. Fortunately, this will only affect you while using Public WiFi, so if you are well protected, using a LAN connection, for instance, than you are not attackable with this method.

In any case, since it has been disclosed, this problem continues to persist. As I've seen on the Register, eBay spokesman Hani Durzy said: "This vulnerability is a well known weakness within the HTTP protocol itself. If the user logs out, it will clear the session. Beyond that, the only thing that can be done about it would be to turn the entire site into SSL - which would be prohibitive on several fronts, including usability."

Google has pretty much filled this hole in the wall, successfully deploying SSL, but Gmail does not use it by default and users have little knowledge that this layer can be enabled. In the meantime, all we can do is wait quietly until they fix it or search the web for programs that may enable SSL on certain sites.

MORE RELATED ARTICLES: FUNNY Way to Hack Gmail The Advantages of Using Gmail Illegal Gmail Activities? Not Allowed, Duh! Dude, Where's My Gmail Account? Come On People, Example@Gmail.com = Example@Googlemail.com!
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


10th September 2007, 07:03 GMT | Copyright (c) 2007 Softpedia | Contact:
Read by 457 user(s) | Rating: | 8 vote(s) so far | Cast your vote:
Gmail, eBay, MySpace – STILL Vulnerable - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT Gmail, eBay, MySpace – STILL Vulnerable

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive