{"id":935,"date":"2007-09-28T09:31:11","date_gmt":"2007-09-28T04:01:11","guid":{"rendered":"http:\/\/www.chiragmehta.info\/chirag\/2007\/09\/28\/gmail-cookie-vulnerability-exposes-users-privacy\/"},"modified":"2007-09-28T09:31:14","modified_gmt":"2007-09-28T04:01:14","slug":"gmail-cookie-vulnerability-exposes-users-privacy","status":"publish","type":"post","link":"https:\/\/www.chiragmehta.info\/chirag\/2007\/09\/28\/gmail-cookie-vulnerability-exposes-users-privacy\/","title":{"rendered":"Gmail cookie vulnerability exposes user&#8217;s privacy"},"content":{"rendered":"<p>Petko Petkov of &#8220;ethical hacking&#8221; group GNUCitizen has developed a proof-of-concept program to steal contacts and incoming e-mails from Google Gmail users.<br \/>\n&#8220;This can be used to forward all your incoming e-mail,&#8221; Pure Hacking security researcher Chris Gatford said. &#8220;It&#8217;s just a proof of concept at the moment, but what they&#8217;re demonstrating is the potential to use this vulnerability for malicious purposes.&#8221; <\/p>\n<p>According to Gatford, attackers could compromise a Gmail account&#8211;using a cross-site scripting vulnerability&#8211;if the victim is logged in and clicks on a malicious link. From that moment, the attacker can take over the session cookies for Gmail and subsequently forward all the account&#8217;s messages to a POP account. <\/p>\n<p>&#8220;If someone picks up on this before Google fixes it&#8211;or if someone knew of the vulnerability before this guy published it&#8211;this could be very damaging to Gmail users,&#8221; he added. <\/p>\n<p>The problem is potentially compounded by Google&#8217;s policy of retaining cookies for two years. <\/p>\n<p>&#8220;Once you&#8217;ve managed to snarf a cookie, you can access (a user&#8217;s) Gmail account without the password for the next two years,&#8221; he said. <\/p>\n<p>Read Complete Hack @ <a href=\"http:\/\/news.zdnet.com\/2100-1009_22-6210353.html\">Zdnet.com<\/a<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Petko Petkov of &#8220;ethical hacking&#8221; group GNUCitizen has developed a proof-of-concept program to steal contacts and incoming e-mails from Google Gmail users. &#8220;This can be used to forward all your incoming e-mail,&#8221; Pure Hacking security researcher Chris Gatford said. &#8220;It&#8217;s just a proof of concept at the moment, but what they&#8217;re demonstrating is the potential [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[167],"class_list":["post-935","post","type-post","status-publish","format-standard","hentry","category-google","tag-google","post-preview"],"_links":{"self":[{"href":"https:\/\/www.chiragmehta.info\/chirag\/wp-json\/wp\/v2\/posts\/935","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.chiragmehta.info\/chirag\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.chiragmehta.info\/chirag\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.chiragmehta.info\/chirag\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.chiragmehta.info\/chirag\/wp-json\/wp\/v2\/comments?post=935"}],"version-history":[{"count":0,"href":"https:\/\/www.chiragmehta.info\/chirag\/wp-json\/wp\/v2\/posts\/935\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.chiragmehta.info\/chirag\/wp-json\/wp\/v2\/media?parent=935"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.chiragmehta.info\/chirag\/wp-json\/wp\/v2\/categories?post=935"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.chiragmehta.info\/chirag\/wp-json\/wp\/v2\/tags?post=935"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}