Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Webmaster > Google News

August 13th, 2007, 09:09 GMT · By Bogdan Popa

Warning! Your Gmail Account Is About to Be Hacked!

SHARE:

Adjust text size:


The Gmail login form
Enlarge picture
A new security hole was discovered in the Gmail protection system by Marcel Richter in May but it seems like the folks from Googleplex ignored the message and avoided fixing the flaw. Let me explain the exploitation procedure as it is described by Philipp Lenssen from Google Blogoscoped.
While you are browsing the Internet, you see a weblink to login into your Google account and obviously, you click on it.

You're then redirected to a Google page that requires you to enter your username and password or, even if your details are saved by the browser, you skip over this step. This is the moment when you're in danger. According to the blogger, you receive a message that the password is wrong so you're required to enter the information once again. Obviously, the hacker steals it and is now able to access your account.

"What happened here is that Google allows you to add a parameter when you link to Google Account login pages. This parameter describes the follow-up page the user should be automatically led to once they've successfully logged-in. Google is smart enough to only allow certain values for this parameter, but there's a hole in this defense," Philipp Lenssen wrote.

He also added that he already contacted the Mountain View company to inform them about the security hole so it seems like we're now protected from successful exploitations of the vulnerability.

As you can see, the entire attack works like a phishing attempt so, if you want to remain 100 percent secure, you should often check the URL of the webpage you're currently on. For example, you can avoid the last step of the exploitation, the one requiring you to enter the password one more time, by checking the website address in the browser that is usually different from the original ones provided by Google.
FILED UNDER:
gmail
hack
attack
security

TELL US WHAT YOU THINK:

1,420 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


The Advantages of Using Gmail

Gmail to Work with Other Instant Messengers!

Gmail: All-In-One Email Solution!

Gmail Domain Dispute Reported in China

Gmail Records Major Downtime Problems

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM