BetaONE will rise again!


Reply
  #1  
Old 28th Sep 07, 12:45 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 31,079
NewsBot will become famous soon enough
Serious vulnerability found in Gmail
Security researcher Petko Petkov has revealed a cross-site request forgery vulnerability in Gmail that makes it possible for a malicious web site to surreptitiously add a filter to a user's Gmail account that forwards e-mail to a third-party address.

Petkov's proof-of-concept exploit for this vulnerability, which has been independently verified but not publicly released, uses a multipart/form-data POST to send instructions to Gmail's internal API. The vulnerability can only be exploited when the user is currently logged in to the Gmail service.

This is the second major Google security vulnerability to be revealed this week. On Monday, security researcher Fernando Bedford provided a proof-of-concept exploit for a Google cross-site scripting vulnerability in Google's Blogspot polls API that facilitated e-mail hijacking and address book sniffing. That vulnerability was fixed by Google shortly after it was reported, but it is presently unclear whether or not the vulnerability discovered by Petkov has been fixed yet.

View: Full Article @ Arstechnica

Read full story...



More...
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Gmail cookie vulnerability exposes user's privacy NewsBot DriverHeaven News 0 27th Sep 07 08:14 PM
Vulnerability Found In D-Link Routers NewsBot NeoWin News 0 19th Jul 06 02:30 PM
14 year old discovers Gmail vulnerability NewsBot NeoWin News 0 2nd Mar 06 01:00 PM
Second Metafile Vulnerability Found in Windows NewsBot NeoWin News 0 10th Jan 06 05:30 PM
GMail Drive shell extension 1.0.5 jakesnake FreeWare & Shareware 0 20th Jan 05 08:45 AM


All times are GMT +1. The time now is 06:44 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.