Whole Network Most Recent TOP10 Hardware Lifestyle Online Services Wireless

 

Gmail security vulnerability

Filed in archive Wireless by Rom Feria on February 01, 2008

ArsTechnica reports what security researcher, Robert Graham, discovered whilst using Google Mail.

Google mail

His technique (nicknamed sidejacking), intercepts session ID cookies from the WiFi signal and used for a number of purposes, including sending and receiving e-mail. This type of attack takes place after the end-user has securely logged on to a service.


This happens even with SSL since Gmail attempts to connect both in SSL-secured mode and non-SSL mode. So when you access the SSL enabled site, if it fails, it will automatically reconnect with non-SSL version. This makes your password vulnerable to sniffing.

The "good" news, however, is that GMail is not the only one affected. :( This may be the wake-up call for all road warriors to make sure that you know when your transactions are secure. I wonder if the direct SMTP and POP/IMAP access to Gmail are also vulnerable.

Advertisement


Permalink: Gmail security vulnerability
Tags: security  vulnerability  SSL  HTTPS  google  gmail  mail  2007  security+vulnerability 

Trackback: http://www.creative-weblogging.com/cgi-bin/mt-tb.pl/112600



Advertisement


Advertisement


RSSrss   | See all blog subscribe options
Googlegoogle   |   What is RSS?
Yahoo!yahoo
AddthisAddThis Feed Button
BloglinesBloglines
Newsletter

Use our search feature to look for other interesting posts

Just this blog Whole network


 
  • Advertise with us

  • Learn more about our advertising options or email advertising - at - creative-weblogging.com or give Luis a call at +1 (650) 331 8047.


  • Other blogs in the same channel in the Creative Weblogging Network







 
Tagcloud: About the blog Accessories Blog Books Business Environment Events Fashion Hardware Headset Health Home Office Humor Internet Internet telephony Legal Lifestyle Marketing Mobile Phones Mouse Multimedia News Online Services Open Formats Protection Small business Software Sponsored Post Storage Wireless