| | #1 (permalink) | |
| Resident USSRian | Please Set Your GMail to Secure Mode I don't know how many of you follow what happens at Defcon, but many of you should, because it is the biggest black-hat conference of the year, newest volnurability vectors get described, and newest tools get put out. Genreally, if a tool is put out, there is generally a fix, such is the case with Surf Jack, a neat tool to steal gmail cookies. Here's the thing, Google, as well as many other giants, set session cookies such that one can access the logged in account over HTTP or HTTPS. Utilizing this neat feature, Mike Perry has created a tool to hijack google cookie data. But utilizing the neat feature allows him to hijack the data, whether you logged in with http or https. It does this quite simply, if your session data is encrypted over HTTPS, next time you send a dns request, the tool forwards you to http:// and the session data is stolen. Luckily for you, well, us, google has a fix. In your gmail settings, scroll all the way down, and select "Always use HTTPS". This will restrict the http access, and disallow the clear passing of the session data. Also remember, any time you use WiFi, to log into an account, ALWAYS log off that account when you are done... My security tip of the day... ---------------- And remember that great question that Pierre-Simon Laplace and Sir Isaac Newton, Andrei Markov and David Hilbert, Richard Feynman and Enrico Fermi, Albert Einstein and Edmund Halley did not come to ask throughout all of their dedication and work: "Who the hell is IMing me?" This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License. ![]() | |
| ||
| | #2 (permalink) | |
| Wedding Planner ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Re: Please Set Your GMail to Secure Mode Thanks again Alex! Can you elaborate on why this is good practice and what could happen (and why) if you do not do this? ---------------- Hypography Science Forums Moderator --- "There are no passengers on Spaceship Earth. We are all crew." - Marshall McLuhan "We must not forget that when radium was discovered no one knew that it would prove useful in hospitals. The work was one of pure science. And this is a proof that scientific work must not be considered from the point of view of the direct usefulness of it." - Marie Curie | |
| ||
| | #3 (permalink) | |
| Resident USSRian | Re: Please Set Your GMail to Secure Mode Because gathering session data wirelessly is even simpler. I love scapy, it's got to be my most favorite python program ever. Tools written on top of scapy are interesting, yet very dangerous, one such tool is called WiFiZoo, aimed as sniffing authentication data, right out of the air... Not just GMail data, any handshake, secure or not... and then with a flick of a mouse (has a very nice web interface) shazaam, you are able to use the data to get into the session, and it does not matter that you are on different IPs, scapy can bend (change) all of that... ---------------- And remember that great question that Pierre-Simon Laplace and Sir Isaac Newton, Andrei Markov and David Hilbert, Richard Feynman and Enrico Fermi, Albert Einstein and Edmund Halley did not come to ask throughout all of their dedication and work: "Who the hell is IMing me?" This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License. ![]() | |
| ||
| | #4 (permalink) | ||
| Wedding Planner ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Re: Please Set Your GMail to Secure Mode Quote:
---------------- Hypography Science Forums Moderator --- "There are no passengers on Spaceship Earth. We are all crew." - Marshall McLuhan "We must not forget that when radium was discovered no one knew that it would prove useful in hospitals. The work was one of pure science. And this is a proof that scientific work must not be considered from the point of view of the direct usefulness of it." - Marie Curie | ||
| |||
| | #5 (permalink) | |
| Resident USSRian | Re: Please Set Your GMail to Secure Mode No, but you can be tricked.... with some recent problems found with DNS you can forward say a dns request to mail.google.com when you were trying to hit msn.com or something, and your cookie will belong to the haxor ---------------- And remember that great question that Pierre-Simon Laplace and Sir Isaac Newton, Andrei Markov and David Hilbert, Richard Feynman and Enrico Fermi, Albert Einstein and Edmund Halley did not come to ask throughout all of their dedication and work: "Who the hell is IMing me?" This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License. ![]() | |
| ||
| | #6 (permalink) | |
| Wedding Planner ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Re: Please Set Your GMail to Secure Mode So how does signing out help? Btw, I checked my DNS servers and they are patched. ![]() ---------------- Hypography Science Forums Moderator --- "There are no passengers on Spaceship Earth. We are all crew." - Marshall McLuhan "We must not forget that when radium was discovered no one knew that it would prove useful in hospitals. The work was one of pure science. And this is a proof that scientific work must not be considered from the point of view of the direct usefulness of it." - Marie Curie | |
| ||
| | #7 (permalink) | |
| Resident USSRian | Re: Please Set Your GMail to Secure Mode ok, if you sign out the cookie data is invalid, and noone can just log in using that... DNS servers are patched, problem is, the dns games will never leave the local network, especially on a wifi net ![]() ---------------- And remember that great question that Pierre-Simon Laplace and Sir Isaac Newton, Andrei Markov and David Hilbert, Richard Feynman and Enrico Fermi, Albert Einstein and Edmund Halley did not come to ask throughout all of their dedication and work: "Who the hell is IMing me?" This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License. ![]() | |
| ||
| | #8 (permalink) | |||
| Wedding Planner ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Re: Please Set Your GMail to Secure Mode Quote:
I see what you're saying though. Quote:
Sorry for all the questions, but I'm generally non-chalant about "lock-down" security and you're making me think that I need to learn about this stuff much more. ---------------- Hypography Science Forums Moderator --- "There are no passengers on Spaceship Earth. We are all crew." - Marshall McLuhan "We must not forget that when radium was discovered no one knew that it would prove useful in hospitals. The work was one of pure science. And this is a proof that scientific work must not be considered from the point of view of the direct usefulness of it." - Marie Curie | |||
| ||||
| | #9 (permalink) | |
| Hypo Contributer | I have several emails G-Mail is not one of them, Question is this only a G-Mail problem? or should I check all of my accounts? Thanks DougF. ---------------- There are many things to be shared with the Four Colors of humanity in our common destiny as one with our Mother the Earth. It is this sharing that must be considered with great care by the Elders and the medicine people who carry the Sacred Trusts, so that no harm may come to people through ignorance and misuse of these powerful forces. Resolution of the Fifth Annual Meetings of the Traditional Elders Circle, 1980 | |
| ||
| | #10 (permalink) | ||||
| Resident USSRian | Re: Please Set Your GMail to Secure Mode Quote:
Quote:
Quote:
er MITM can be executed using other protocols. One can create a rougue DHCP server on a network (you can see how dangerous that is), one can create a rougue DNS server, or bring down the network dns server and set up a computer to act as one (that would be really deep penetration)... I mean there are a plethora of ways to do it on a wired network... ---------------- And remember that great question that Pierre-Simon Laplace and Sir Isaac Newton, Andrei Markov and David Hilbert, Richard Feynman and Enrico Fermi, Albert Einstein and Edmund Halley did not come to ask throughout all of their dedication and work: "Who the hell is IMing me?" This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License. ![]() | ||||
| |||||
![]() |
| Bookmarks |
| Tags |
| defcon, gmail, http, https, mail, mike, perry, surf jack, wifi |
« AMD Rolls Out Their Radeon HD 4870 X2 Cards
|
MIT Student's MBTA Payment and Card Systems Volnurability Research »
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| How Do I Secure My Box? | alexander | Tutorials | 11 | 08-19-2008 04:26 PM |
| emacs matlab mode | sanctus | Computer Science | 7 | 04-16-2008 06:12 AM |
| Anybody tried Gmail yet? | IrishEyes | Watercooler | 9 | 02-27-2005 11:28 PM |
All times are GMT -8. The time now is 04:41 PM.




















