Paul's Tech Talk

Menu

  • Home
  • About me

Tag: CSRF Attack

Gmail Vulnerable to a Change PW Attack!

PaulMarch 3, 2009

Securiteam has made an announcement that Gmail has an issue.  I will quote:

GMail is vulnerable to CSRF attacks in the “Change Password” functionality. The only token for authenticate the user is a session cookie, and this cookie is sent automatically by the browser in every request.

[ad#ad2-right]An attacker can create a page that includes requests to the “Change password” functionality of GMail and modify the passwords of the users who, being authenticated, visit the page of the attacker.

The attack is facilitated since the “Change Password” request can be realized across the HTTP GET method instead of the POST method that is realized habitually across the “Change Password” form.

[Via Securiteam]

One way to prevent this to a point is right now having GMAIL automatically connect securely.  You would go into your settings in gmail and make sure it uses https connection:
Making sure it says to USE HTTPSThis is one way to prevent the cookie attack but is still needing to be fixed.   Since it is using the HTTP GET method it should use the HTTPS method as soon as you try accessing the site.   Google needs to change to the HTTPS Get method instead to prevent this type of attack.   If you have any other ideas for Google just leave a comment.

Posted In Securiteam, Security, Vulnebilities, vulnerabilityTagged Account, Change Password, connection, CSRF Attack
106 readers
Feed Statistics

RSS Feed

RSS feed

Recent Posts

  • Windows 10 was End of Life – So I decided to go to Linux Mint using ChatGPT!
  • She Said I Was the Problem… Until Everyone Saw the Truth
  • Diary of a Narcissist’s Supply: The Ugly Truth Behind the Fake Love
  • Microsoft Flight Simulator 2024 – Not recommended (Day 5)
  • The Dark Side of Job Hunting: Are You Being Tricked by Fake Interviews?

Recent Comments

  • She Said I Was the Problem… Until Everyone Saw the Truth – Paul's Tech Talk on Diary of a Narcissist’s Supply: The Ugly Truth Behind the Fake Love
  • The Shocking Link Between Rising Unemployment and Fake Job Listings! – Paul's Tech Talk on Prevailing winds of Job Scams being on the Rise in 2024
  • Is Pathrise the Best Career Accelerator? A Comprehensive Review on Navigating the Job Market Maze: How Pathrise Can Guide you to your next Career!
  • Navigating the Job Market Maze: How Pathrise Can Guide you to your next Career! – Paul's Tech Talk on Job Hunting 101: Mastering the Art of Applying for Positions
  • More signs of Economic Trouble for the US! – Paul's Tech Talk on In Depth Investigation of the Job Market and How it looks

Archives

Categories

The form you have selected does not exist.

© 2026 Paul's Tech Talk. BlueBird Theme by JGT.
Back To Top
Verified by ExactMetrics
Mastodon Mastodon