Gmail cookie vulnerability exposes user's privacy

Petko Petkov of "ethical hacking" group GNUCitizen has developed a proof-of-concept program to steal contacts and incoming e-mails from Google Gmail users.

"This can be used to forward all your incoming e-mail," Pure Hacking security researcher Chris Gatford said. "It's just a proof of concept at the moment, but what they're demonstrating is the potential to use this vulnerability for malicious purposes."

According to Gatford, attackers could compromise a Gmail account--using a cross-site scripting vulnerability--if the victim is logged in and clicks on a malicious link. From that moment, the attacker can take over the session cookies for Gmail and subsequently forward all the account's messages to a POP account.

"If someone picks up on this before Google fixes it--or if someone knew of the vulnerability before this guy published it--this could be very damaging to Gmail users," he added.

The problem is potentially compounded by Google's policy of retaining cookies for two years.

"Once you've managed to snarf a cookie, you can access (a user's) Gmail account without the password for the next two years," he said.

While the obvious risk is to the home user, many organizations could be exposed, since they do not filter employee e-mails sent from work to personal accounts, he added.

"People do use private accounts to store work information," IBRS security analyst James Turner said. "I've worked at one organization where this was implicitly expected, because the mail server at the time was so unreliable. But that scenario is certainly less than optimal.

"In an ideal world, an organization would be able to draw a line in the sand and say that corporate data does not pass this point. The current reality is that there are Gen-Y workers who are sharing information with each other on multiple alternative communication channels--Gmail and Facebook included."

One work-around is to use Gmail through Firefox and disable JavaScript. While this limits user access to many components of popular Web sites, it will protect against the potential threat.

Developers at many large enterprises are not aware of the power of cross-site scripting, said Pure Hacking's Gatford. "In the last year or so, (XSS vulnerabilities) have been used by attackers to grab cookie values and therefore gain access to normally password-protected sites."

"When you have organizations like Google spending countless man-hours reducing security vulnerabilities...you can imagine how bad the actual situation is for other organizations," Gatford said.

Gatford advised organizations to use resources such as the Open Web Application Security Project, or OWASP, which offers free tools to help write secure code and allow testing for XSS vulnerabilities.

Google was unavailable to comment.

Liam Tung of ZDNet Australia reported from Sydney.

More from News.com on this story's topics

E-mail clients

Create an email alert | RSS feed

Security threats

Create an email alert | RSS feed

Google

Create an email alert | RSS feed

See more CNET content tagged:
XSS, Gmail, cookie, vulnerability, attacker

Add a Comment (Log in or register) 6 comments (Page 1 of 1)
Google has bugs!!!
by FutureGuy September 27, 2007 9:44 AM PDT
OMG, though that could never happen. Welcome to the real world.
Reply to this comment View reply
This is unique to Google?
by Fat Drunk and Stupid September 27, 2007 11:53 AM PDT
Someone exploited a vulnerability in cross-site scripting to gain access to a Gmail account and it is Google's fault? The same thing can't be done to gain access to any other web service? What if I'm logged into my CNET account and I click on a malicious link that snarfs my CNET cookie? Is this possible or is this vulnerability exclusive to Google? Less fear and more facts please.
Reply to this comment
Tell me it ain't so...Google can do no wrong...
by fred dunn September 28, 2007 5:29 PM PDT
Typical for a web app. Memo to all CIOs out there that chose gmail: HA-HA.
Reply to this comment View reply
Powered by Jive Software
advertisement
Click Here
RSS Feeds
Add headlines from CNET News.com to your homepage or feedreader.
Google
Yahoo
MSN
More feeds available in our RSS feed index.
Today's Top Stories
Yahoo responds to Icahn
Your Web activity, logged and loaded
Florida seeks to fine Verizon for bad service
Deconstructing Wikipedia at the Berkman Center
Nintendo tops April game console sales
Most Popular Stories
CBS to buy CNET Networks
Images: Microsoft telescope puts universe on your desktop
Intel Germany executive reportedly confirms Atom-based iPhone
Xbox 360 hits 10 million sold in U.S.
Photos: Microsoft previews 2008 Xbox games
Markets

Market news, charts, SEC filings, and more

Related quotes

Google (0.82%) 4.70 581.00
Dow Jones Industrials (0.73%) 94.28 12,992.66
S&P 500 (1.06%) 14.91 1,423.57
NASDAQ (1.48%) 37.03 2,533.73
CNET TECH (1.67%) 29.18 1,781.41
  Symbol Lookup



advertisement
On TechRepublic: 3 habits of highly ineffective employees
Advanced
search
Advanced
search
Visit other CNET Networks sites: