ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Google: no evidence of a Gmail vulnerability

By | November 26, 2008, 7:19am PST

Summary: Following the speculations on the resurrection of what’s thought to be an already fixed Gmail flaw which could assist in domain name hijackings, yesterday Google commented that their investigation indicated that the recent domain hijacks should be attributed to a phishing campaign, rather than to a Gmail flaw. The phishers was silently adding filter rules [...]

Gmail Phishing AttackFollowing the speculations on the resurrection of what’s thought to be an already fixed Gmail flaw which could assist in domain name hijackings, yesterday Google commented that their investigation indicated that the recent domain hijacks should be attributed to a phishing campaign, rather than to a Gmail flaw. The phishers was silently adding filter rules to the compromised Gmail accounts, then resetting the passwords so that the accounting data for a particular service or a domain would be quietly forwarded to the attacker’s mailboxes.

“With help from affected users, we determined that the cause was a phishing scheme, a common method used by malicious actors to trick people into sharing their sensitive information. Attackers sent customized e-mails encouraging web domain owners to visit fraudulent websites such as “google-hosts.com” that they set up purely to harvest usernames and passwords. These fake sites had no affiliation with Google, and the ones we’ve seen are now offline. Once attackers gained the user credentials, they were free to modify the affected accounts as they desired. In this case, the attacker set up mail filters specifically designed to forward messages from web domain providers.”

Phishing campaigns impersonating Google are in fact becoming so prevalent, that an entire market segment within the underground economy is starting to emerge, which is primarily trading with stolen AdSense accounts. Access to these accounts is obtained either through data mining already infected with malware hosts part of their botnet, or through plain simple phishing campaigns taking advantage of typosquatting in order to visually social engineer an end user, consider the following examples :

adwords.google.com.index.main.update .qwertycn.cn
adsense.google.com.server.main.update .dirty-boy.cn
edit.google.com.main.update .the-format.cn
google.com.urchin.js .7traff.cn
google.com.urchin.js .axa1.cn
adwords.google-secutiyserv .com
google.com.br.updatesoftware.index.d81f0f02cd6a877358cde8fbdbad89a5 .qwertycn.cn
google.com.updatesoftware.index.d81f0f02cd6a877358cde8fbdbad89a5 .rootit2.info
adwords.google.com.session-69680268279998252722.92444537268559875865 .com68.ru

Two weeks ago, Google quietly fixed a critical XSS vulnerability affecting its accounts login page, which at the time was providing a fully realistic opportunity for malicious attackers to turn into “cookie monsters” and hijack user’s sessions on a large scale.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter
4
Comments

Join the conversation!

Just In

RE: Google: no evidence of a Gmail vulnerability
lovedong 13th Sep
Thank you for this!! rolex watches
0 Votes
+ -
Gmail problems ignored by google!
Quirkly 27th Nov 2008
Apparently my gmail page was hacked and infected by the clickjacking worm/trojan/bot. After months (April? August to date)struggling with an undetectable (by AV/computer pros) clickjacking problem, I infected a new laptop computer by clicking on the link to my sophos AV download on my gmail page. No mail downloaded, no other link clicked, used different network, was running mcafee that came with the computer.
No I had not updated windows as yet.

Because of the months of problems, I was hoping to get sophos installed before I did anything else. I have obtained NO HELP or acknowledgment from Gmail. Another user wrote that he had been infected by the PER_SALITY.JER virus, tracked back to his Gmail. Minor attention was given to my report of the associated google desktop problems (uninstalled GDT ASAP, greyed out GDT swirl near cursor recurred suspiciously, related to attempts to scan with online AV, etc. I am still infected with the clickjacker. However gmail is now forwarded to a paid address site with no new infections acquired from reading email.
I also used google documents and infected a different computer from that site.

Gmail ignores issues, fails to respond to information provided by users or requests for help. Google was excellent, now I am concerned about the entire concept, and their inability to maintain the necessary security.
0 Votes
+ -
dude...
bladeoz 27th Nov 2008
Gmail is in Beta and free... I mean, come on give them a break, they're a warm and loving company after all who have only the user's interests truely at heart.



Sorry to hear you got screwed around
Thank you for this!! rolex watches
0 Votes
+ -
RE: Google: no evidence of a Gmail vulnerability
birumut Updated - 5th May 2011
Great!!! thanks for sharing this information to us !
seslisohbet seslichat

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix