Google’s Security Hole Caused by Cookies

Please note this security issue has already been fixed by Google.

I thought this was odd that Google had a security hole due to the amount of cookie’s their users store on the computers. It seems that if someone wanted, they could trick gMail users into visiting a page on Google (I’m guessing a page on GooglePages) and grab all those cookies.

Since Google offers a ton of services that run off of your Google Account, I’m guessing there are different cookies for each service and all of them can be obtained to let a hacker:

  • Get into my Google Docs & Spreadsheets application and read and modify documents I saved there
  • Read subjects from my Gmail inbox, as well as the first few words of these emails, by adding a Gmail module to the Google
  • Personalized Homepage
  • View my Google Accounts page
  • Enter my Google Reader
  • Read my private Google Notebook
  • View my complete Google search history (for as long as I had the search history feature enabled in Google)

However, the user could not read an entire E-Mail or view the events in a calendar or change the master account password (if they were, it would be a much bigger deal).

Technorati Tags: , ,

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • blinkbits
  • BlinkList
  • blogmarks
  • co.mments
  • connotea
  • del.icio.us
  • De.lirio.us
  • digg
  • Fark
  • feedmelinks
  • Furl
  • LinkaGoGo
  • Ma.gnolia
  • NewsVine
  • Netvouz
  • RawSugar
  • Reddit
  • scuttle
  • Shadows
  • Simpy
  • Smarking
  • Spurl
  • TailRank
  • Wists
  • YahooMyWeb
  • BlogMemes
  • Blue Dot
  • DotNetKicks
  • DZone
  • Fleck
  • Gwar
  • Hemidemi
  • IndiaGram
  • IndianPad
  • kick.ie
  • Linkter
  • MisterWong
  • MyShare
  • Netscape
  • PopCurrent
  • ppnow
  • Rec6
  • Slashdot
  • SphereIt
  • StumbleUpon
  • Taggly
  • Technorati
  • Webride
  • Wykop


Popularity: 3%


Leave a Reply

Subscribe to Modern SEO News

Get this widget from Widgetbox

Sponsors



Blogroll

Resources