UK Broadband Forum
   Broadband forum

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 08-03-2007, 09:13 PM
Senior Member
 
Join Date: Jul 2007
Posts: 151
GMail WIFI hack revealed
Security researchers have presented a GMail hack at the Black Hat conference today.

The hack involves sniffing the cookies returned by Gmail after the user has logged in, even though the actual login process is handled by HTTPS the rest of the site is HTTP based allowing the cookie to be sniffed.

Once you have the captured cookie this will allow you unlimited access to that person's mail account.

To perform this hack you need to be able to sniff HTTP traffic, and thats where the WIFI comes in with the way most internet traffic is routed now its very difficult to sniff these cookies except by means of an insecure WIFI connection.

Other Web2.0 applications may also be at risk from this kind of attack, although banking applications are unlikely to be at risk.

Jen
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2  
Old 08-03-2007, 09:33 PM
Senior Member
 
Join Date: Jul 2007
Location: U.K.
Posts: 128
Mozilla Firefox has a great add-on for editing cookies. I've added it and looked at my own before.

I think though that the info is Hashed, so may need to be cracked, read, and then re-inserted.

This isn't good for Gmail, people can SMTP from there standard accounts.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3  
Old 08-03-2007, 09:40 PM
Senior Member
 
Join Date: Jul 2007
Posts: 151
Thats the point of the hack, you just need to have the cookie, no changing the cookie needed.

Seems the cookie doesnt time out, and isnt locked to a particular IP.

Jen
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4  
Old 08-20-2007, 05:00 AM
Senior Member
 
Join Date: Aug 2007
Posts: 233
The best way is to delete your cookies everytime you log out but mostly the cookies are timed out after sometime no I don't think that someone can actually hack in your account after you log out from your account properly.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5  
Old 08-20-2007, 08:17 AM
Senior Member
 
Join Date: Jul 2007
Posts: 151
Actually Niki thats exactly what this hack does, the existence of the valid cookie is enough to give you access to that site. Whether you delete, remove or even eat the cookie doesn't stop it existing elsewhere giving someone else access to the site.

Of course it does depend a lot on how the programmers devised the authentication system, whether its locked to a particular IP or whether logging out invalidates the cookie on the remote side but on the whole developers dont think of these things.

Jen
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6  
Old 08-20-2007, 12:36 PM
Senior Member
 
Join Date: Aug 2007
Posts: 134
Originally Posted by JenniP View Post
Of course it does depend a lot on how the programmers devised the authentication system, whether its locked to a particular IP or whether logging out invalidates the cookie on the remote side but on the whole developers dont think of these things.

Jen
So is that the key, to invalidate as well as to delete the cookie? As someone who has never coded in anything more powerful than Basic, is that hard to do?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7  
Old 08-20-2007, 02:50 PM
Senior Member
 
Join Date: Jul 2007
Posts: 226
This is always good information to have. Does anyone know what google plans to do about since they are the ones that have not properly setup security to avoid issues such as this.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:01 PM.



Content Relevant URLs by vBSEO 3.3.1