5 ms·
CSRF vulnerability found in Gmail; Google not willing to fix it
- dguido 18y agoYHBT
- cperciva 18y agoNot much of a vulnerability -- the attacker still has to guess the victim's password.
- pmjordan 18y agoOnly because gmail enforces somewhat safe passwords. Does it look them up in a dictionary though? You could probably harvest even long-ish dictionary-based passwords this way if an attacker manages to embed this in a sufficiently high traffic page.
- tptacek 18y agoI don't think you get it. If you could guess a user's password, why would you bother with this elaborate CSRF attack?
- pmjordan 18y agoFair point. I guess if you had access to a botnet, you could attempt a similarly broad attack; with this you'd only need access to a popular, less scrupulous site. (porn, torrent/warez, etc. sites spring to mind)
- sh1mmer 18y agoStep 1. Send Gmail user an email for some free Porn, Get Rich quick, etc Step 2a. Ask them to create a username/password for their free Porn Step 2b. Use the password to change their Gmail account login, download all their other account information and lock them out. Step 3. Steal all the money from their bank account using the information from their Gmail account Alternatively: Step 1. As above Step 2a. Show the user lots of free porn, etc to keep them on your site. Step 2b. Do a scripted dictionary attack against the user's account to change their password using their cookies. Step 3. As above The essential point here is that using a non-cookie session based url identifier for things that change the state of a user's account is a must. At Yahoo! we call it a "crumb". Essentially print a unique (at least to the user) and verifiable key on your pages. Check for that key before accepting any requests to change stuff. E.g: Linking document <?php //This should really be a chunk from /dev/random $secret = 'unicorns'; $time = time(); setcookie("timestamp", $time); $crumb = sha1($secret . $time); ?> <a href="doAmazingStuff.php?crumb=<?=$crumb?>">Do Amazing Stuff</a> Action Document <?php $secret = 'unicorns'; if (isset($_GET['crumb'])) { $crumb_val = sha1($secret . $_COOKIE['timestamp']); if ($_GET['crumb'] == $crumb_val) { amazingStuff(); } else { showError('Crumb is invalid'); } } else { showError('No crumb to validate'); }
- DenisM 18y agoGmail asks old password before allowing to set new one, so the attack script is brute-forcing the password by submitting requests from a hostile page visited by the victim. It will take 150 million HTTP requests to brute-force a 6-letter password from 26 possible letters. I suspect red flags will come up at google after first couple million requests. Or the victim will leave the hostile page he was lured to.
- nebula 18y agoIf the cracker gets to send a couple million requests per victim, I won't be surprised if she manages to crack passwords of many users. Blind brute force is definitely not the sharpest knife in the drawer; Dictionary based attacks might prove much more powerful when it comes to cracking average Joe's password.
- jrockway 18y agoAccording to this article, Gmail disallows weak passwords. So brute-forcing is going to be relatively ineffective.
- extension 18y agoI believe the (poorly explained) rationale behind the alert is that the CSRF allows the attacker to brute force the password without triggering a captcha, as happens on the main login page after a couple of bad logins. If you sent out spam containing a CSRF link that tried a dozen or so of the most common passwords, you might get a few hits, though I don't know why anyone would bother. Still, if I were Google, I would just fix it. I'm a bit surprised that Google doesn't have a generic authenticity system for all of their forms, or if they do, why it would be omitted from this one form.
- tarkin2 18y agoIf google allows strong passwords such as "Password1" then I'm sure quite a few users would pick such a simple password, and I'm sure attackers realise this. It would be wise if google forced the user to enter the capcha on password change. Disallowing GET would be good as well. Otherwise attackers would would have to use POST, which would mean tricking the user to submit a html form, and I'm unsure if you can send multiple POST requests per submit.
- msluyter 18y agoI understand that this threat isn't particularly worrisome, but articles like this one remind me just how dependent I've become on gmail and how vulnerable as a result. I've now got years of info including everything from purchase receipts to personal conversations of high sentimental value. If someone were to either hack my password or simply cause my account to be disabled I'd be seriously screwed. I'm now feeling like I need some sort of backup or other protective measure.
- nikblack 18y agonot mentioned in the original post is that the change password field also gives you the option of entering the answer to your 'secret question' rather than your password as the second token. you replace the password query params with: &group1=IdentityAnswer&IdentityAnswer=ANSWER_GUESS not as improbable to guess since Google do not enforce a standard on the secret question answer (ie. with 'place you were born' you could just list major cities and probably get a hit every so often) if you had access to a high traffic site (thank-you wordpress hax) you would probably harvest a number of accounts using this in an IFRAME pretty quickly. you just need to add some javascript to somehow inform you which ones were a success.