August 20th, 2008, 01:55 PM
Gmail Account Hacking Tool
Quick solution: log into gmail, go to settings and at the bottom choose "Always use https". I found that it wasn't set on my system.
A tool that automatically steals IDs of non-encrypted sessions and breaks into Google Mail accounts has been presented at the Defcon hackers’ conference in Las Vegas.
Last week Google introduced a new feature in Gmail that allows users to permanently switch on SSL and use it for every action involving Gmail, and not only, authentication. Users who did not turn it on now have a serious reason to do so as Mike Perry, the reverse engineer from San Francisco who developed the tool is planning to release it in two weeks.
When you log in to Gmail the website sends a cookie (a text file) containing your session ID to the browser. This file makes it possible for the website to know that you are authenticated and keep you logged in for two weeks, unless you manually hit the sign out button. When you hit sign out this cookie is cleared.
Even though when you log in, Gmail forces the authentication over SSL (secure Socket Layer), you are not secure because it reverts back to a regular unencrypted connection after the authentication is done. According to Google this behavior was chosen because of low-bandwidth users, as SLL connections are slower.
The problem lies with the fact that every time you access anything on Gmail, even an image, your browser also sends your cookie to the website. This makes it possible for an attacker sniffing traffic on the network to insert an image served from http://mail.google.com
and force your browser to send the cookie file, thus getting your session ID. Once this happens the attacker can log in to the account without the need of a password. People checking their e-mail from public wireless hotspots are obviously more likely to get attacked than the ones using secure wired networks.
Perry mentioned that he notified Google about this situation over a year ago and even though eventually it made this option available, he is not happy with the lack of information. “Google did not explain why using this new feature was so important” he said. He continued and explained the implications of not informing the users, “This gives people who routinely log in to Gmail beginning with an https:// session a false sense of security, because they think they’re secure but they’re really not.”
If you are logging in to your Gmail account from different locations and you would like to benefit from this option only when you are using unsecured networks, you can force it by manually typing https://mail.google.com
before you log in. This will access the SSL version of Gmail and it will be persistent over your entire session and not only during authentication.
August 20th, 2008, 06:25 PM
Yup, there is no reason not to set it. I changed over a little while ago after I found out it was an option. Its so nice :-)
August 20th, 2008, 09:44 PM
OHHH thanks. Mine wasnt set to anything.
The world is a dangerous place to live; not because of the people who are evil, but because of the people who don't do anything about it.
August 22nd, 2008, 10:03 PM
Thank you very much for the heads up. I will pass this along.
\"Those of us that had been up all night were in no mood for coffee and donuts, we wanted strong drink.\"
August 23rd, 2008, 02:15 PM
Hmm i have mine just setup so i can access it through outlook.
Haven't actually logged in using there actual site, so i doubt that i will need to really worry about this.
But none the less thanks for the heads up.
August 23rd, 2008, 04:48 PM
Besides setting this option, you can force the session to stay https by including a https when you type in the address.
Instead of just typing www.gmail.com or gmail.com or etc. type out https://gmail.com and the whole session will be over https, not just the login.
Who knows why they wouldn't make this a default... They go through the trouble of ensuring that imap and pop3 connections are done over ssl... Why not force https too?!
BTW: It's nice to see that google docs and the like can now be used over SSL. I really liked the idea of google docs when it came out. The only reason I never used it and denied it on my corporate network was because of the lack of SSL. I know a lot of IT professionals who share various scripts and docs between each other using google docs. I would never join them because of the lack of SSL.
Last edited by phishphreek; August 23rd, 2008 at 04:52 PM.
is a firefox extension that gives you stats on how long you have quit smoking, how much money you\'ve saved, how much you haven\'t smoked and recent milestones. Very helpful for people who quit smoking and used to smoke at their computers... Helps out with the urges.
August 23rd, 2008, 05:15 PM
Edit scratch that, in ff3 it stayed in a secure session, but under ie after authenticating it dropped into a normal session.??
Last edited by t34b4g5; August 23rd, 2008 at 05:18 PM.
August 24th, 2008, 11:38 AM
As I suspected, it would seem that the problem extends beyond Google?
A security researcher has been in discussions with Google on an exploit he plans to release that would allow a hacker to easily intercept someone's communications with supposedly secure Web sites over an unsecured Wi-Fi network, but other sites, like Facebook, Yahoo Mail, and Hotmail, remain vulnerable.
If you cannot do someone any good: don't do them any harm....
As long as you did this to one of these, the least of my little ones............you did it unto Me.
What profiteth a man if he gains the entire World at the expense of his immortal soul?
August 25th, 2008, 12:28 AM
Well at least Google is actually doing something about this, they are taking a step in the write direction and auto turning the switch on for everyone.
It is also very possible that Google will make it so that the "always encrypt" mode is automatically enabled when people first log in via "https://gmail.google.com" instead of having to go into settings and enable it manually, Perry says.
That way those that are less tech savy will also be in the clear.
August 25th, 2008, 02:44 AM
Thanks for the heads up, mine wasn't set to anything either!
Originally Posted by t34b4g5
Yeah where as if it were Microsoft, well you know...
By ThePreacher in forum Miscellaneous Security Discussions
Last Post: December 14th, 2006, 08:37 PM
By 3rr0r in forum The Security Tutorials Forum
Last Post: December 1st, 2004, 05:31 AM
By jehnx in forum AntiOnline's General Chit Chat
Last Post: October 30th, 2004, 07:04 AM
By ss2chef in forum AntiOnline's General Chit Chat
Last Post: September 6th, 2004, 11:19 PM