Front Office Football Central  

Go Back   Front Office Football Central > Archives > FOFC Archive
Register FAQ Members List Calendar Mark Forums Read Statistics

Reply
 
Thread Tools
Old 04-23-2009, 09:53 AM   #1
Alan T
Hall Of Famer
 
Join Date: Dec 2002
Location: Mass.
Security issues regarding Web based email (including Gmail vulnerability)

I tried to find a decent way to title this post so as to not cause too much panic.

A new Gmail vulnerability was found last month that can allow a potential breaking in of your account if you happen to have another browser tab open to a "hacker infected" webpage. This new hole is by far more difficult for a hacker to take advantage or or exploit than the previously discovered cross site scripting exploits that were discovered when you had multiple tabs open.

If interested in this topic, there is a pretty decent article here that I feel tries to take the discussion down a level to be understood by more users as well as give some various possible better "usage" practices for users with web based emails:

Gmail accounts hacked via unpatched hole
__________________
Couch to ??k - From the couch to a Marathon in roughly 18 months.



Alan T is offline   Reply With Quote
Old 04-23-2009, 10:01 AM   #2
Fidatelo
Pro Starter
 
Join Date: Nov 2002
Location: Winnipeg, MB
I'm curious if Chrome and IE8's usage of a separate process per tab would render this exploit ineffective?
__________________
"Breakfast? Breakfast schmekfast, look at the score for God's sake. It's only the second period and I'm winning 12-2. Breakfasts come and go, Rene, but Hartford, the Whale, they only beat Vancouver maybe once or twice in a lifetime."
Fidatelo is offline   Reply With Quote
Old 04-23-2009, 10:08 AM   #3
Alan T
Hall Of Famer
 
Join Date: Dec 2002
Location: Mass.
Quote:
Originally Posted by Fidatelo View Post
I'm curious if Chrome and IE8's usage of a separate process per tab would render this exploit ineffective?

Do they share cookies across their tabs? ie: if you log in to a site on one tab and then go to a different tab for that site, do you still stay logged in on the same session?

if so then the same thing applies. This particular exploit is taking advantage of the Gmail's change password feature because it only uses a session cookie as the authenticative verifier. As long as the session remains valid across tabs, it can be used to exploit this.

Like I said before though, this is far less of a risk then the Cross site scripting vulnerability previously found which was present in ALL major browsers since this exploit also requires a brute force attack of some form as well to accomplish it.
__________________
Couch to ??k - From the couch to a Marathon in roughly 18 months.


Alan T is offline   Reply With Quote
Old 04-23-2009, 10:17 AM   #4
Radii
Head Coach
 
Join Date: Jul 2001
showing a lack of knowledge on exactly how session IDs and cookies work... is another copy of the browser treated differently than a new tab? If I run gmail in one copy of firefox that never opens up new tabs/new sites, and then do all my other browsing and open up all my tabs in a separate instance of firefox, does that resolve the issue?
Radii is offline   Reply With Quote
Old 04-23-2009, 10:20 AM   #5
Passacaglia
Coordinator
 
Join Date: Oct 2000
Location: Big Ten Country
Quote:
Originally Posted by Alan T View Post
I tried to find a decent way to title this post so as to not cause too much panic.



Don't check your email, it will kill you!!!
Passacaglia is offline   Reply With Quote
Old 04-23-2009, 10:25 AM   #6
Alan T
Hall Of Famer
 
Join Date: Dec 2002
Location: Mass.
Quote:
Originally Posted by Radii View Post
showing a lack of knowledge on exactly how session IDs and cookies work... is another copy of the browser treated differently than a new tab? If I run gmail in one copy of firefox that never opens up new tabs/new sites, and then do all my other browsing and open up all my tabs in a separate instance of firefox, does that resolve the issue?

Same answer that I gave above probably. If you can open a new window of Gmail in the other copy of firefox and it still uses the previous session cookies, then you are still at risk. I don't personally know how the different browsers handle different windows, so don't want to mislead anyone. I know with the firefox 3.1 beta they have a mode called "Private browsing" that they set up to protect against cross site scripting vulnerabilities that you can use to ensure no cookies get carried over to other sessions at all. I don't believe that is in the current release Firefox browser (it might be, I'm not sure)

Quote:
Originally Posted by Passacaglia View Post
Don't check your email, it will kill you!!!

I should have totally titled this thread that, but then everyone would think it is a script for a new movie.
__________________
Couch to ??k - From the couch to a Marathon in roughly 18 months.


Alan T is offline   Reply With Quote
Old 04-23-2009, 11:50 AM   #7
DanGarion
Coordinator
 
Join Date: Nov 2003
Location: The Great Northwest
I think they all use the same sessions, since if you are logged in on one you can open another tab and you are still logged in.
__________________
Los Angeles Dodgers
Check out the FOFC Groups on Facebook! and Reddit!
DON'T REPORT ME BRO!
DanGarion is offline   Reply With Quote
Old 04-23-2009, 12:12 PM   #8
Mustang
Grizzled Veteran
 
Join Date: Oct 2000
Location: Wisconsin
Thank god I just have a hotmail account.
__________________
You, you will regret what you have done this day. I will make you regret ever being born. Your going to wish you never left your mothers womb, where it was warm and safe... and wet. i am going to show you pain you never knew existed, you are going to see a whole new spectrum of pain, like a Rainboooow. But! This rainbow is not just like any other rainbow, its...
Mustang is offline   Reply With Quote
Old 04-23-2009, 01:24 PM   #9
flere-imsaho
Coordinator
 
Join Date: Sep 2004
Location: Chicagoland
I miss the Internet of 1991 (when I was first introduced to it).
flere-imsaho is offline   Reply With Quote
Old 04-23-2009, 01:57 PM   #10
Alan T
Hall Of Famer
 
Join Date: Dec 2002
Location: Mass.
Quote:
Originally Posted by flere-imsaho View Post
I miss the Internet of 1991 (when I was first introduced to it).

You enjoyed that tn3270 session to look through Minnesota's gopher server for good sites to download the original DOOM from? Be warned though, that 1MB file download takes several hours to download via xmodem
__________________
Couch to ??k - From the couch to a Marathon in roughly 18 months.


Alan T is offline   Reply With Quote
Old 04-23-2009, 01:59 PM   #11
flere-imsaho
Coordinator
 
Join Date: Sep 2004
Location: Chicagoland
Dude, gopher was awesome.
flere-imsaho is offline   Reply With Quote
Old 04-23-2009, 02:08 PM   #12
Galaril
Pro Starter
 
Join Date: Jan 2004
Quote:
Originally Posted by DanGarion View Post
I think they all use the same sessions, since if you are logged in on one you can open another tab and you are still logged in.

I can confirm they do use the same session cookie. This was an exploit I have used in a past organization where I was an ethical hacker.
Galaril is offline   Reply With Quote
Old 04-23-2009, 02:14 PM   #13
DanGarion
Coordinator
 
Join Date: Nov 2003
Location: The Great Northwest
Quote:
Originally Posted by Alan T View Post
You enjoyed that tn3270 session to look through Minnesota's gopher server for good sites to download the original DOOM from? Be warned though, that 1MB file download takes several hours to download via xmodem

Give me back Lynx.
__________________
Los Angeles Dodgers
Check out the FOFC Groups on Facebook! and Reddit!
DON'T REPORT ME BRO!
DanGarion is offline   Reply With Quote
Old 04-23-2009, 02:20 PM   #14
Ksyrup
This guy has posted so much, his fingers are about to fall off.
 
Join Date: Nov 2000
Location: In Absentia
Although I've had a GMail account as my primary email address for at least 4-5 years, I rarely, if ever, check it online. I mostly read it on my BB, and then either delete it then or download it straight to my home computer and mess with it there. I really have no reason to go to gmail.com.
__________________
M's pitcher Miguel Batista: "Now, I feel like I've had everything. I've talked pitching with Sandy Koufax, had Kenny G play for me. Maybe if I could have an interview with God, then I'd be served. I'd be complete."
Ksyrup is offline   Reply With Quote
Old 04-23-2009, 02:22 PM   #15
Alan T
Hall Of Famer
 
Join Date: Dec 2002
Location: Mass.
Quote:
Originally Posted by DanGarion View Post
Give me back Lynx.

I still use lynx all the time, that really isn't out dated at all. I often have network devices that are on linux based platforms that I have to configure remotely but use a web gui. So I have to console in and configure via a text only web gui to provide them the correct network information to be alive on the network before I can finish configuring them via a normal web browser over the network.
__________________
Couch to ??k - From the couch to a Marathon in roughly 18 months.


Alan T is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump


All times are GMT -5. The time now is 11:45 AM.



Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.