FreddysHouse  

Go Back   FreddysHouse > Techie Discussion

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 29th August 2008, 08:20 AM
Darthshearer's Avatar
One of Freddy's beloved
 
Join Date: 22nd Dec 2003
Location: Leeds
Posts: -
Darthshearer has a spectacular aura aboutDarthshearer has a spectacular aura aboutDarthshearer has a spectacular aura about
GMail Easy To Hack?

Any truth in this?

I use Gmail all the time, but not daft enough to save passwords like but still a little scarey?

Quote:
Let’s talk security and why you should take advantage of Gmail’s recent SSL feature, and why you might want to be careful using other non-SSL webmail services.

But first, make sure your connection is secured using SSL.

How do you know a connection is secured by SSL? The handy “s” after “http” will tell you. For example, https://mail.google.com is encrypted while http://mail.google.com is not. You can force an encryption by adding the “s” yourself, or by turning on “Always use https” from the Browser Connection settings of your Gmail account.



Why? Because without it, anyone can easily hack someone’s account and in two weeks it is going to get even easier. Mike Perry, a reverse engineer from San Francisco, announced his intention to release his Gmail Account Hacking Tool to the public. According to a quote at Hacking Truths, Perry mentioned he was unimpressed with how Google presented the SSL feature as less-than-urgent. It is urgent, and here’s why.

Before Gmail released the ability to automatically encrypt your Gmail connections, your browser/server interactions went something like this:

Your Browser: Hey there Gmail, I want in. Here’s my encrypted login.
Gmail Servers: Hey there, browser. I see your encrypted login fits what I have here. If you want to keep talking to me, I will need to see proof of your login, but don’t bother encrypting it for me. Here is your unencrypted email.

Your Browser: Great. I want to read this particular email, my Gmail login is: webmonkey@wired.com and my password is: monkeylove. My name is John Hanks Doe and my social security number is 123-45-6789.
Gmail Servers: Sure, here you go. I see you are leaving for vacation with the house unlocked this weekend. Say, is this your credit card information?
Guy packet sniffing your wi-fi from Starbucks: Cool!

It’s a little more complex than that (and a little less goofy and dramatic), but the theory is sound. Using encryption at login only is the equivalent of setting up a toll booth in the desert.

Here’s the exploit: All it takes to steal someone’s Gmail login account is to intercept any transaction since every single one, even images, pass a cookie which contains the session information.

Spoof the session, and you get free reign to the account — including the ability to change your password. Every non-SSL session is in plain text. With a little determination, any bored, disaffected youth could read your email and change your password within a day. Is it really that easy? Here’s a useful tutorial we found via Google search. When the Gmail Account Hacking Tool is eventually released, it couldn’t be any easier.

With SSL, however, the interaction looks something like this:

Your Browser: xz6RV-BRJViqzNJROECslw
Gmail Servers: jx3iC96D3kuZ_IWNrK461w
Your Browser: PxIryG_P3_3_vRENZdWxMQ

The real thing would be even longer in length, and perfectly unreadable. SSL requires a key generated on your end and on the Gmail server’s end. There’s no way for the local guy at Starbucks to get those keys and unencrypt the data by packet sniffing.

Makes you feel a little vulnerable knowing all your public information was so nakedly exposed over the past few years, huh? Did Google know about this?

It turns out they were well aware of it. The reason Google didn’t grant users the SSL feature before, according to Perry, was because SSL is expensive. It takes a lot of bandwidth and time on both the receiver and transmitter sides to generate keys and encrypt data. Slower data connections would experience a lagging Gmail experience.

Packet sniffing for session information is not a new thing, and is bound to get even more familiar due to how easy it is. Keep in mind, it is not just Gmail which passes account information outside of SSL encrypted connections. There are many sites around the internet that are still vulnerable to this exploit. Protecting your wifi connection with WEP isn’t foolproof either. Your best bet is to use SSL whenever you are transferring information valuable to you, and to avoid sites that don’t use it at all.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 29th August 2008, 10:31 AM
MYstIC G's Avatar
Sitter of Couches, Destroyer of Deity's

One of the mods
Super Moderator
 
Join Date: 22nd Dec 2003
Location: Thornton Heath, England
Posts: -
MYstIC G is a splendid one to beholdMYstIC G is a splendid one to beholdMYstIC G is a splendid one to beholdMYstIC G is a splendid one to beholdMYstIC G is a splendid one to beholdMYstIC G is a splendid one to beholdMYstIC G is a splendid one to beholdMYstIC G is a splendid one to behold
If it bothers you, force GMail to use SSL in the settings

Official Gmail Blog: Making security easier
__________________
Doing God's work since two thousand and something...
Quote:
Originally Posted by Trem View Post
Thank god for Meg and his vicious mod stick
# MYstIC G.com / v3 # ConsoleForums.org #
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

  FreddysHouse > Techie Discussion

Tags
easy, gmail, hack, page not found, [HELP]

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Gmail WPKenny Techie Discussion 7 19th April 2008 05:35 AM
Got Gmail? Gamah Off-Topic 7 27th February 2006 09:02 PM
Gmail! Ingafgrinn Macabre Off-Topic 26 22nd July 2005 05:49 AM
Easy realm points+Easy levelin :P microhard RvR Discussions 29 7th February 2005 01:00 PM
Gmail TheJkWhoSaysNi Techie Discussion 12 28th June 2004 11:43 PM


All times are GMT +1. The time now is 11:13 PM.


Powered by: vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
Copyright (c) 2003-2008, Freddy. All rights reserved.
Page generated in 0.27042 seconds with 14 queries using server 193.138.95.50

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109