28 Sep 2007
Google has patched a recently reported Gmail flaw that could allow attackers to steal information from inside a user account.
The vulnerability was discovered by independent security researcher Petko Petkov, who classified it as a cross-site request forgery.
The attack is triggered when a user visits a website containing malicious code while logged into Gmail. The code executes a special command to access the Gmail account and sets up a new filter without the user's knowledge.
An attacker could configure the filter to forward any archived or future messages with certain keywords or senders' names to another email account.
Petkov did not release any details about the attack until Google had issued a fix.
The researcher argued that the attack could be more dangerous than system-based malware because a filter could be used to pick out precise personal details, such as bank account information.
"In an age when all the data is in the cloud, it makes no sense for the attackers to go after your box," Petkov wrote. "It is a lot simpler to install one of these persistent backdoor/spyware filters."
A Google spokesperson confirmed the vulnerability to vnunet.com but stressed that no attacks had been reported.
Users looking to verify that their Gmail accounts are still secure can check their active email filters by clicking on the 'Filters' tab in Gmail's 'Settings' panel.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Field/Site Engineering Manager/Leader Brief: Polar...
Product Manager, Open Repository (ref:BMC/PMR) End...
Java/J2EE Software Developer/Programmer - Dotcom/ eCommerce...
Field/Site Engineering Manager/Leader Brief: Polar...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?