Science Forums
User Name
Password
Science Social Network
home    members    help/rules    who is online    contact   

Go Back   Science Forums > Physical Sciences Forums > Computer Science
Become a science forums sponsor today
Reply
 
LinkBack Thread Tools
Old 08-13-2008   #1 (permalink)
alexander's Avatar
Resident USSRian

Hypography Staff Member
Administrator
Gallery Curator
Dev Team Member

Latest blog entry:
Open-Source HIDS
 
alexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant future
Send a message via AIM to alexander
 



Please Set Your GMail to Secure Mode

I don't know how many of you follow what happens at Defcon, but many of you should, because it is the biggest black-hat conference of the year, newest volnurability vectors get described, and newest tools get put out. Genreally, if a tool is put out, there is generally a fix, such is the case with Surf Jack, a neat tool to steal gmail cookies.

Here's the thing, Google, as well as many other giants, set session cookies such that one can access the logged in account over HTTP or HTTPS. Utilizing this neat feature, Mike Perry has created a tool to hijack google cookie data. But utilizing the neat feature allows him to hijack the data, whether you logged in with http or https. It does this quite simply, if your session data is encrypted over HTTPS, next time you send a dns request, the tool forwards you to http:// and the session data is stolen.

Luckily for you, well, us, google has a fix. In your gmail settings, scroll all the way down, and select "Always use HTTPS". This will restrict the http access, and disallow the clear passing of the session data. Also remember, any time you use WiFi, to log into an account, ALWAYS log off that account when you are done...

My security tip of the day...


----------------
And remember that great question that Pierre-Simon Laplace and Sir Isaac Newton, Andrei Markov and David Hilbert, Richard Feynman and Enrico Fermi, Albert Einstein and Edmund Halley did not come to ask throughout all of their dedication and work: "Who the hell is IMing me?"


This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License.
Reply With Quote
Old 08-13-2008   #2 (permalink)
freeztar's Avatar
Wedding Planner

Hypography Staff Member
Moderator
Editor
Silver Subscription
Sponsor

Latest blog entry:
Things to bring
 
freeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond repute
 



Re: Please Set Your GMail to Secure Mode

Thanks again Alex!

Quote:
Originally Posted by alexander View Post
Also remember, any time you use WiFi, to log into an account, ALWAYS log off that account when you are done...
Can you elaborate on why this is good practice and what could happen (and why) if you do not do this?


----------------
Hypography Science Forums Moderator
---
"There are no passengers on Spaceship Earth. We are all crew." - Marshall McLuhan

"We must not forget that when radium was discovered no one knew that it would prove useful in hospitals. The work was one of pure science. And this is a proof that scientific work must not be considered from the point of view of the direct usefulness of it." - Marie Curie
Reply With Quote
Old 08-13-2008   #3 (permalink)
alexander's Avatar
Resident USSRian

Hypography Staff Member
Administrator
Gallery Curator
Dev Team Member

Latest blog entry:
Open-Source HIDS
 
alexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant future
Send a message via AIM to alexander
 



Re: Please Set Your GMail to Secure Mode

Because gathering session data wirelessly is even simpler. I love scapy, it's got to be my most favorite python program ever. Tools written on top of scapy are interesting, yet very dangerous, one such tool is called WiFiZoo, aimed as sniffing authentication data, right out of the air... Not just GMail data, any handshake, secure or not... and then with a flick of a mouse (has a very nice web interface) shazaam, you are able to use the data to get into the session, and it does not matter that you are on different IPs, scapy can bend (change) all of that...


----------------
And remember that great question that Pierre-Simon Laplace and Sir Isaac Newton, Andrei Markov and David Hilbert, Richard Feynman and Enrico Fermi, Albert Einstein and Edmund Halley did not come to ask throughout all of their dedication and work: "Who the hell is IMing me?"


This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License.
Reply With Quote
Old 08-13-2008   #4 (permalink)
freeztar's Avatar
Wedding Planner

Hypography Staff Member
Moderator
Editor
Silver Subscription
Sponsor

Latest blog entry:
Things to bring
 
freeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond repute
 



Re: Please Set Your GMail to Secure Mode

Quote:
Originally Posted by alexander View Post
Because gathering session data wirelessly is even simpler. I love scapy, it's got to be my most favorite python program ever. Tools written on top of scapy are interesting, yet very dangerous, one such tool is called WiFiZoo, aimed as sniffing authentication data, right out of the air... Not just GMail data, any handshake, secure or not... and then with a flick of a mouse (has a very nice web interface) shazaam, you are able to use the data to get into the session, and it does not matter that you are on different IPs, scapy can bend (change) all of that...
But it can only sniff it out as it is being transmitted, correct?


----------------
Hypography Science Forums Moderator
---
"There are no passengers on Spaceship Earth. We are all crew." - Marshall McLuhan

"We must not forget that when radium was discovered no one knew that it would prove useful in hospitals. The work was one of pure science. And this is a proof that scientific work must not be considered from the point of view of the direct usefulness of it." - Marie Curie
Reply With Quote
Old 08-13-2008   #5 (permalink)
alexander's Avatar
Resident USSRian

Hypography Staff Member
Administrator
Gallery Curator
Dev Team Member

Latest blog entry:
Open-Source HIDS
 
alexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant future
Send a message via AIM to alexander
 



Re: Please Set Your GMail to Secure Mode

No, but you can be tricked.... with some recent problems found with DNS you can forward say a dns request to mail.google.com when you were trying to hit msn.com or something, and your cookie will belong to the haxor


----------------
And remember that great question that Pierre-Simon Laplace and Sir Isaac Newton, Andrei Markov and David Hilbert, Richard Feynman and Enrico Fermi, Albert Einstein and Edmund Halley did not come to ask throughout all of their dedication and work: "Who the hell is IMing me?"


This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License.
Reply With Quote
Old 08-13-2008   #6 (permalink)
freeztar's Avatar
Wedding Planner

Hypography Staff Member
Moderator
Editor
Silver Subscription
Sponsor

Latest blog entry:
Things to bring
 
freeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond repute
 



Re: Please Set Your GMail to Secure Mode

So how does signing out help?

Btw, I checked my DNS servers and they are patched.


----------------
Hypography Science Forums Moderator
---
"There are no passengers on Spaceship Earth. We are all crew." - Marshall McLuhan

"We must not forget that when radium was discovered no one knew that it would prove useful in hospitals. The work was one of pure science. And this is a proof that scientific work must not be considered from the point of view of the direct usefulness of it." - Marie Curie
Reply With Quote
Old 08-13-2008   #7 (permalink)
alexander's Avatar
Resident USSRian

Hypography Staff Member
Administrator
Gallery Curator
Dev Team Member

Latest blog entry:
Open-Source HIDS
 
alexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant future
Send a message via AIM to alexander
 



Re: Please Set Your GMail to Secure Mode

ok, if you sign out the cookie data is invalid, and noone can just log in using that...

DNS servers are patched, problem is, the dns games will never leave the local network, especially on a wifi net


----------------
And remember that great question that Pierre-Simon Laplace and Sir Isaac Newton, Andrei Markov and David Hilbert, Richard Feynman and Enrico Fermi, Albert Einstein and Edmund Halley did not come to ask throughout all of their dedication and work: "Who the hell is IMing me?"


This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License.
Reply With Quote
Old 08-13-2008   #8 (permalink)
freeztar's Avatar
Wedding Planner

Hypography Staff Member
Moderator
Editor
Silver Subscription
Sponsor

Latest blog entry:
Things to bring
 
freeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond reputefreeztar has a reputation beyond repute
 



Re: Please Set Your GMail to Secure Mode

Quote:
Originally Posted by alexander View Post
ok, if you sign out the cookie data is invalid, and noone can just log in using that...
But wouldn't they use it right after you log in anyways.
I see what you're saying though.
Quote:
DNS servers are patched, problem is, the dns games will never leave the local network, especially on a wifi net
At the risk of going off topic, how exactly would that work? Is it like, someone is wardriving, finds your SSID and monitors traffic acting as a relay between the router and the victim? How would it work for a wired network?

Sorry for all the questions, but I'm generally non-chalant about "lock-down" security and you're making me think that I need to learn about this stuff much more.


----------------
Hypography Science Forums Moderator
---
"There are no passengers on Spaceship Earth. We are all crew." - Marshall McLuhan

"We must not forget that when radium was discovered no one knew that it would prove useful in hospitals. The work was one of pure science. And this is a proof that scientific work must not be considered from the point of view of the direct usefulness of it." - Marie Curie
Reply With Quote
Old 08-14-2008   #9 (permalink)
DougF's Avatar
Hypo Contributer

Silver Subscription
Sponsor

 



Lightbulb Re: Please Set Your GMail to Secure Mode

I have several emails G-Mail is not one of them, Question is this only a
G-Mail problem? or should I check all of my accounts?

Thanks DougF.


----------------
There are many things to be shared with the Four Colors of humanity in our common destiny as one with our Mother the Earth. It is this sharing that must be considered with great care by the Elders and the medicine people who carry the Sacred Trusts, so that no harm may come to people through ignorance and misuse of these powerful forces.

Resolution of the Fifth Annual Meetings of the Traditional Elders Circle, 1980
Reply With Quote
Old 08-14-2008   #10 (permalink)
alexander's Avatar
Resident USSRian

Hypography Staff Member
Administrator
Gallery Curator
Dev Team Member

Latest blog entry:
Open-Source HIDS
 
alexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant futurealexander has a brilliant future
Send a message via AIM to alexander
 



Re: Please Set Your GMail to Secure Mode

Quote:
Originally Posted by freezy
But wouldn't they use it right after you log in anyways.
50/50 there, probably not, but they may...

Quote:
acting as a relay between the router and the victim
well, no, there is a jump you've made there, in order to act as a relay, you need to poison arp. If someone is wardriving, they are just monitoring packets on an AP, not in between, just catching rf data going out in all directions... MITM comes if they are able to connect, identify their target and successfully execute a Man In The Middle, whether by ARP poisoning, or by taking over the AP. At this point all your traffic is flowing through them, and yeah, all your base are belong to them.

Quote:
How would it work for a wired network?
similarly, arp poisoning works on a wired network to execute a MITM, and unless you are running one of those nifty 5k cisco boxes thats all up to date, your wired network is very volnurable to a MITM, and as i said, once the attacker is successfully executing that, you are screwed er

MITM can be executed using other protocols. One can create a rougue DHCP server on a network (you can see how dangerous that is), one can create a rougue DNS server, or bring down the network dns server and set up a computer to act as one (that would be really deep penetration)... I mean there are a plethora of ways to do it on a wired network...


----------------
And remember that great question that Pierre-Simon Laplace and Sir Isaac Newton, Andrei Markov and David Hilbert, Richard Feynman and Enrico Fermi, Albert Einstein and Edmund Halley did not come to ask throughout all of their dedication and work: "Who the hell is IMing me?"


This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 License.
Reply With Quote
Reply

Bookmarks

Tags
defcon, gmail, http, https, mail, mike, perry, surf jack, wifi


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
How Do I Secure My Box? alexander Tutorials 11 08-19-2008 04:26 PM
emacs matlab mode sanctus Computer Science 7 04-16-2008 06:12 AM
Anybody tried Gmail yet? IrishEyes Watercooler 9 02-27-2005 11:28 PM


All times are GMT -8. The time now is 04:41 PM.

Hypography?

Hypography [n.]: A combination of "hyperlink" and "bibliography" - ie, a list of links to electronic documents. Comparable to discography and bibliography, but not cartography.

We have been online since May 2000, and aim to be the best place to find and share science-related content of all kinds.

Share the love!

Please add more science to your life. Use our RSS feeds on your blog, your portal, or your favorite feedreader!

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc. Copyright © 2000-2008 Hypography
Part of the Hypography - Science for Everyone Network