Malicious Setting Up of Filters in Gmail?

Sunday, November 23, 2008

I was reading my Reader feeds , and I found this important post about Gmail ,and I thought it would be good if you get informed as well.

Brandon at GeekCondition reports of a Gmail security vulnerability which lets an attacker set up automated filters in your Gmail account, provided the attacker manages to lure you onto a page of theirs first. Brandon does not post the full exploit (obtaining a certain variable for this exploit “is tricky but possible”, Brandon says, adding that he’s “not going to tell you how to do it, if you search hard enough online you’ll find out how”), and I’m not sure if this works on just any browser. As automated filters can trigger mail addressed to you to be forwarded to someone else (and trashed in your account), some already had their domain name kidnapped due to this issue. To Gmail users, Brandon suggests “Check your filters and make sure that nothing seems out of the ordinary.”

