<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; gmail vulnerability</title>
	<atom:link href="http://www.ghacks.net/tag/gmail-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 09:43:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New Google Mail Security Vulnerability Emerges</title>
		<link>http://www.ghacks.net/2008/11/24/new-google-mail-security-vulnerability-emerges/</link>
		<comments>http://www.ghacks.net/2008/11/24/new-google-mail-security-vulnerability-emerges/#comments</comments>
		<pubDate>Mon, 24 Nov 2008 20:33:22 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Email]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[email security]]></category>
		<category><![CDATA[email vulnerability]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[gmail security]]></category>
		<category><![CDATA[gmail vulnerability]]></category>
		<category><![CDATA[google-mail]]></category>
		<category><![CDATA[web mail]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8512</guid>
		<description><![CDATA[News about domain hijackings came to light in the last weeks. The commonality was that all victims were using Google Mail as the primary email address of their websites. Yesterday a proof of concept for a Gmail security flaw was posted at the Geek Condition blog which explains how the attacker was able to hijack [...]]]></description>
			<content:encoded><![CDATA[<p>News about domain hijackings came to light in the last weeks. The commonality was that all victims were using Google Mail as the primary email address of their websites. <a href="http://geekcondition.com/2008/11/23/gmail-security-flaw-proof-of-concept/">Yesterday</a> a proof of concept for a <a href="http://www.ghacks.net/2009/02/09/gmail-90-tools-and-tips-to-make-you-a-gmail-pro/">Gmail</a> security flaw was posted at the Geek Condition blog which explains how the attacker was able to hijack the domain names.</p>
<p>The attacker basically set filters in Gmail to forward emails from the domain registrar to another email account. To ensure that the account owner would not notice the mails they were set to be deleted afterwards.</p>
<p>Most domain registrars offer web forms that can be used to retrieve account information. Godaddy for instance provides web forms to retrieve the username and reset the password of an account. They do send out emails to the primary email account. Those emails are however forwarded and deleted so that they can only be accessed by the attacker.</p>
<p><span id="more-8512"></span>The two emails will contain the account&#8217;s username and a new password which can be used to log into the account and initiate a domain transfer to another registrar.</p>
<p>The exploit makes use of a specially prepared website to steal the Google Mail cookie from the user to set the filter in an hidden iframe. This is why the account owners were never logged out of their account by the attacker. He never had physical access to the account. But the filter was enough to hijack the domains.</p>
<p>Gmail users should regularly check their Filters to make sure that none exist that have not been added by them. A better solution would be to retrieve the emails from a desktop email client like Thunderbird or Microsoft Outlook instead.No word yet from the Google Mail team about the vulnerability.</p>

	Tags: <a href="http://www.ghacks.net/tag/email/" title="Email" rel="tag">Email</a>, <a href="http://www.ghacks.net/tag/email-security/" title="email security" rel="tag">email security</a>, <a href="http://www.ghacks.net/tag/email-vulnerability/" title="email vulnerability" rel="tag">email vulnerability</a>, <a href="http://www.ghacks.net/tag/gmail/" title="gmail" rel="tag">gmail</a>, <a href="http://www.ghacks.net/tag/gmail-security/" title="gmail security" rel="tag">gmail security</a>, <a href="http://www.ghacks.net/tag/gmail-vulnerability/" title="gmail vulnerability" rel="tag">gmail vulnerability</a>, <a href="http://www.ghacks.net/tag/google-mail/" title="google-mail" rel="tag">google-mail</a>, <a href="http://www.ghacks.net/tag/web-mail/" title="web mail" rel="tag">web mail</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/07/10/tracking-gmail-account-usage/" title="Tracking Gmail Account Usage (July 10, 2008)">Tracking Gmail Account Usage</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/10/29/google-mail-account-security-tips/" title="Google Mail Account Security Tips (October 29, 2009)">Google Mail Account Security Tips</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/07/14/gmail-increases-email-security-with-phishing-protection/" title="Gmail Increases Email Security With Phishing Protection (July 14, 2009)">Gmail Increases Email Security With Phishing Protection</a> (7)</li>
	<li><a href="http://www.ghacks.net/2009/06/30/use-gmail-to-host-and-share-photos/" title="Use Gmail To Host And Share Photos (June 30, 2009)">Use Gmail To Host And Share Photos</a> (6)</li>
	<li><a href="http://www.ghacks.net/2009/03/11/truemark-email-identification/" title="Truemark Email Identification (March 11, 2009)">Truemark Email Identification</a> (5)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/11/24/new-google-mail-security-vulnerability-emerges/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
