Gmail Vulnerable to Sidejacking

Talk about and discuss various advancements and achievents in the arts and sciences of invention and modification; computers, sciences, mathematics, and technology for all.
Post Reply
User avatar
AYHJA
392
Posts: 37990
Joined: Fri Sep 17, 2004 2:25 pm
Location: Washington, D.C.
Contact:

Gmail Vulnerable to Sidejacking

#1

Post by AYHJA »

Image

Published: February 01, 2008 - 12:50PM CT

By Joel Hruska (arstechnica.com) -- Last August, security researcher and CEO of Errata Security Robert Graham demonstrated just how easy it could be access potentially serious user information. His technique (nicknamed sidejacking), intercepts session ID cookies from the WiFi signal and used for a number of purposes, including sending and receiving e-mail. This type of attack takes place after the end-user has securely logged on to a service. Virtually all companies provide a secure login portal, but many do not secure the connection thereafter, which exposes the end-user to potential hacking as described above. During his demonstration at the time, Graham said that Google Mail users could switch to https://mail.google.com and secure their session from such snooping—but he's now backed away from and qualified that statement.

According to Graham, Google's JavaScript code makes HTTP requests in the background via an XMLHttpRequest. By default, these requests are SSL-encrypted—but if SSL fails, they change to nonencrypted mode. When a user attempts to connect to a WiFi hotspot, Google Mail attempts to connect with SSL both enabled and disabled. Even if the attempt fails, session-ID cookies are still transmitted to the router, and can therefore be captured by anyone sitting nearby with an appropriately configured software suite.

Source: http://tinyurl.com/26mzxr

BBcode:
Hide post links
Show post links
User avatar
zaphodz
Posts: 1265
Joined: Thu Jun 29, 2006 10:56 am

Re: Gmail Vulnerable to Sidejacking

#2

Post by zaphodz »

Actually I think this was fixed by Google late last year sometime.

BBcode:
Hide post links
Show post links
Post Reply