Gmail
An attacker could configure Gmail filters to forward any archived or future messages

Google plugs Gmail security hole

Filter-injection attack allowed forwarding of emails to third parties

Written by Shaun Nichols in California

Google has patched a recently reported Gmail flaw that could allow attackers to steal information from inside a user account.

The vulnerability was discovered by independent security researcher Petko Petkov, who classified it as a cross-site request forgery.

The attack is triggered when a user visits a website containing malicious code while logged into Gmail. The code executes a special command to access the Gmail account and sets up a new filter without the user's knowledge.

An attacker could configure the filter to forward any archived or future messages with certain keywords or senders' names to another email account.

Petkov did not release any details about the attack until Google had issued a fix.

The researcher argued that the attack could be more dangerous than system-based malware because a filter could be used to pick out precise personal details, such as bank account information.

"In an age when all the data is in the cloud, it makes no sense for the attackers to go after your box," Petkov wrote. "It is a lot simpler to install one of these persistent backdoor/spyware filters."

A Google spokesperson confirmed the vulnerability to vnunet.com but stressed that no attacks had been reported.

Users looking to verify that their Gmail accounts are still secure can check their active email filters by clicking on the 'Filters' tab in Gmail's 'Settings' panel.

Tags:

Further reading

Google touts storage upgrades

Storage plans start at $20 a year for 6GB   More...

Google makes appeal to packrats

Company set to offer extra hosting space   More...

Google ready to unleash the GPhone

Search giant "pumping millions" into mobile strategy   More...

Google profits fall as Microsoft breaks $50bn barrier

Google praises core business, while Microsoft rides out $1bn Xbox hit   More...

Related articles

Mozilla takes second shot at Firefox flaw

Company issues new update for QuickTime vulnerability   More...

Apple patches QuickTime flaw

Windows vulnerability allowed scripted attacks   More...

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Apple QuickTime exploit goes wild

Streaming media flaw used to push malware   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement