
Recently, SecureTeam has made public a flaw in Google Gmail. In fact, a well-proven vulnerability could expose Gmail to CSRF attacks (Cross Site Request Forgery) in the “Change Password” functionality, letting malicious people change the password of the most famous webmail.
Reading from the SecureTeam website:
“GMail is vulnerable to CSRF attacks in the “Change Password” functionality. The only token for authenticate the user is a session cookie, and this cookie is sent automatically by the browser in every request. An attacker can create a page that includes requests to the “Change password” functionality of GMail and modify the passwords of the users who, being authenticated, visit the page of the attacker. The attack is facilitated since the “Change Password” request can be realized across the HTTP GET method instead of the POST method that is realized habitually across the “Change Password” form.”
At the moment the only countermeasure to prevent the hijacking is to have Gmail automatically connect securely. To do that just login your Gmail, click Settings and locate at the end of the page the Browser Connection Settings. At this point just enable the “Always use HTTPS” and you are done.
Tags: Google App, news, security
Related ArticlesLatest Articles
- How to Automatically Login (Access) to Windows 8
- How to See and Read Unread, Archived and Sent Messages on Facebook
- Switch to the New Facebook Profile Layout (Timeline)
- How to Discover and Recover All Stored Passwords in your Windows Computer
Leave a Comment
Web Talk is best viewed in Firefox.
Comments
How to change language in Windows 7: i thought upon installation of Windows they warn you that you can not change the...
Can I Turn on Facebook Chat Auto Reply?: Thanks for explaining, otherwise it would have been a good option, but there are...
How to fix “Windows Explorer has stopped working” in Windows 7: simple remember if you download some new app....
How to Fix uTorrent not Working on Windows 7: desai .. first exit from process .. then try to uninstall
Use online Virtual Windows Operating System directly on your browser: a
Download 64-bit Windows 7 Build 7077 DVD ISO leaked version: hai ptoravo a disinstallare msn con l’applicazione...
Right click on shortcuts icons don’t show “open file location” in Vista: The sorhensect provided above...
Uninstall and Remove AVG Security Search Toolbar and AVG Secure Search: google jobb
Microsoft launches innovative translate widget for blogs: Definitely! It’s rlelay weird at first but...
Small, Hilarious List of Funny Google Translate Tricks: Try this: men are men and men do the cooking, translate to Dutch,...