<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Google GMail E-mail Hijack Technique</title>
	<atom:link href="http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Mon, 12 Dec 2011 19:56:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
	<item>
		<title>By: Gmail touchÃ© par une trÃ¨s inquiÃ©tante faille 0-day â€” SecurityVibes Magazine</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-129781</link>
		<dc:creator>Gmail touchÃ© par une trÃ¨s inquiÃ©tante faille 0-day â€” SecurityVibes Magazine</dc:creator>
		<pubDate>Fri, 25 Mar 2011 14:36:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-129781</guid>
		<description>[...] dires. La publication de quelques bribes d&#8217;explications et diverses captures d&#8217;Ã©cran sur gnucitizen.org en disent cependant long sur les risques potentiels encourus par les [...]</description>
		<content:encoded><![CDATA[<p>[...] dires. La publication de quelques bribes d&#8217;explications et diverses captures d&#8217;Ã©cran sur gnucitizen.org en disent cependant long sur les risques potentiels encourus par les [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: La preuve que la sÃ©curitÃ© est un Ã©chec &#124; Linux-backtrack.com</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-129726</link>
		<dc:creator>La preuve que la sÃ©curitÃ© est un Ã©chec &#124; Linux-backtrack.com</dc:creator>
		<pubDate>Wed, 16 Feb 2011 18:38:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-129726</guid>
		<description>[...] sÃ©curitÃ© de mes fournisseurs de messagerie (Free, Gmail, etc.). Autant dire pas grand-chose non plus, mÃªme si jâ€™utilise de fausses rÃ©ponses aux [...]</description>
		<content:encoded><![CDATA[<p>[...] sÃ©curitÃ© de mes fournisseurs de messagerie (Free, Gmail, etc.). Autant dire pas grand-chose non plus, mÃªme si jâ€™utilise de fausses rÃ©ponses aux [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hosting Industry Watch &#187; Googleâ€™s Gmail Privacy and Security Policies</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-129724</link>
		<dc:creator>Hosting Industry Watch &#187; Googleâ€™s Gmail Privacy and Security Policies</dc:creator>
		<pubDate>Mon, 14 Feb 2011 19:33:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-129724</guid>
		<description>[...] information by offering a number of industry-leading protections.â€ Nevertheless, Gmail has been hijacked on numerous occasions, which has led to data theft, data loss, and domain name [...]</description>
		<content:encoded><![CDATA[<p>[...] information by offering a number of industry-leading protections.â€ Nevertheless, Gmail has been hijacked on numerous occasions, which has led to data theft, data loss, and domain name [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Internet Industry Watch &#187; Googleâ€™s Gmail Privacy and Security Policies</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-129723</link>
		<dc:creator>Internet Industry Watch &#187; Googleâ€™s Gmail Privacy and Security Policies</dc:creator>
		<pubDate>Mon, 14 Feb 2011 19:27:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-129723</guid>
		<description>[...] information by offering a number of industry-leading protections.â€ Nevertheless, Gmail has been hijacked on numerous occasions, which has led to data theft, data loss, and domain name [...]</description>
		<content:encoded><![CDATA[<p>[...] information by offering a number of industry-leading protections.â€ Nevertheless, Gmail has been hijacked on numerous occasions, which has led to data theft, data loss, and domain name [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ethical Hacking Forum</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-129248</link>
		<dc:creator>Ethical Hacking Forum</dc:creator>
		<pubDate>Thu, 28 Oct 2010 07:46:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-129248</guid>
		<description>Phishing - Phishing is by far the most used and easiest method. The attacker simply sets up a page that looks exactly like the real email login page and tricks people into entering their login information.

Update: Check out the new post on how to create your own phishing page here.</description>
		<content:encoded><![CDATA[<p>Phishing &#8211; Phishing is by far the most used and easiest method. The attacker simply sets up a page that looks exactly like the real email login page and tricks people into entering their login information.</p>
<p>Update: Check out the new post on how to create your own phishing page here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: video videolar</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-128659</link>
		<dc:creator>video videolar</dc:creator>
		<pubDate>Thu, 15 Jul 2010 22:13:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-128659</guid>
		<description>Nicolae, refers can be spoofed, not to mention that you can configure your browser not to send them at all. Therefore, CSRF protection based on refers only is not a solution. The only solution is to implement random tokens per request and store their values within the form you want to check for a CSRF condition. This works and this is what the Google folks tried to do, although their implementation was seriously flawed.</description>
		<content:encoded><![CDATA[<p>Nicolae, refers can be spoofed, not to mention that you can configure your browser not to send them at all. Therefore, CSRF protection based on refers only is not a solution. The only solution is to implement random tokens per request and store their values within the form you want to check for a CSRF condition. This works and this is what the Google folks tried to do, although their implementation was seriously flawed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Janet</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-128640</link>
		<dc:creator>Janet</dc:creator>
		<pubDate>Sun, 11 Jul 2010 05:52:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-128640</guid>
		<description>wow i didnt know that was possible!</description>
		<content:encoded><![CDATA[<p>wow i didnt know that was possible!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gmaildeki bÃ¼yÃ¼k hata!</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-128583</link>
		<dc:creator>gmaildeki bÃ¼yÃ¼k hata!</dc:creator>
		<pubDate>Tue, 22 Jun 2010 16:54:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-128583</guid>
		<description>[...] iÃ§erisinde tekrar hesabÄ±nÄ±za girmeye Ã§alÄ±ÅŸÄ±n.  HacklendiÄŸini Anlatan Ä°ngilizce KaynaÄŸa burdan ulasabilirsiniz. Gmailâ€™deki AÃ§Ä±ÄŸÄ±n KapandÄ±ÄŸÄ±nÄ± Anlatan KaynaÄŸa ise buradan [...]</description>
		<content:encoded><![CDATA[<p>[...] iÃ§erisinde tekrar hesabÄ±nÄ±za girmeye Ã§alÄ±ÅŸÄ±n.  HacklendiÄŸini Anlatan Ä°ngilizce KaynaÄŸa burdan ulasabilirsiniz. Gmailâ€™deki AÃ§Ä±ÄŸÄ±n KapandÄ±ÄŸÄ±nÄ± Anlatan KaynaÄŸa ise buradan [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Woodz</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-128573</link>
		<dc:creator>John Woodz</dc:creator>
		<pubDate>Mon, 21 Jun 2010 05:30:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-128573</guid>
		<description>Was once hacked by watever means i dont know but all contact addresses in my account were being send an email using my gmail account by some hacker perporting to be me.! since am a general mind i stopped using gmail was the best i kuld do i hav no idea about java scripting or watever technical terms u talkn here bt i just wana be safe do i doubt technogy en go stone age !</description>
		<content:encoded><![CDATA[<p>Was once hacked by watever means i dont know but all contact addresses in my account were being send an email using my gmail account by some hacker perporting to be me.! since am a general mind i stopped using gmail was the best i kuld do i hav no idea about java scripting or watever technical terms u talkn here bt i just wana be safe do i doubt technogy en go stone age !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: web security trends 2010 &#124; From Information to Intelligence</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-128541</link>
		<dc:creator>web security trends 2010 &#124; From Information to Intelligence</dc:creator>
		<pubDate>Sun, 06 Jun 2010 18:56:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-128541</guid>
		<description>[...] Another long lasting example that emphases that knowledge is essential to web security is CSRF attacks: Even 4 years after the media put this kind of attack under the spotlight there is still people wondering if it is really dangerous.Â  If you still don&#8217;t believe that it is dangerous, ask the people who had their Gmail account backdoored. [...]</description>
		<content:encoded><![CDATA[<p>[...] Another long lasting example that emphases that knowledge is essential to web security is CSRF attacks: Even 4 years after the media put this kind of attack under the spotlight there is still people wondering if it is really dangerous.Â  If you still don&#8217;t believe that it is dangerous, ask the people who had their Gmail account backdoored. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Edward</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-128401</link>
		<dc:creator>Edward</dc:creator>
		<pubDate>Thu, 25 Mar 2010 07:12:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-128401</guid>
		<description>2 points. 

1. the perp could create the filter temporarily then delete it &amp; repeat etc. how would one know it have ever been there?
2. i just discovered gmail messages can be &#039;deleted forever&#039; so one may never know what emails have been sent/received. this is not a good idea from Gmail. all historic entries should be traceable from the logs.</description>
		<content:encoded><![CDATA[<p>2 points. </p>
<p>1. the perp could create the filter temporarily then delete it &amp; repeat etc. how would one know it have ever been there?<br />
2. i just discovered gmail messages can be &#8216;deleted forever&#8217; so one may never know what emails have been sent/received. this is not a good idea from Gmail. all historic entries should be traceable from the logs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: éšå¿ƒåšå®¢ &#187; Blog Archive &#187; CSRFâ€”è·¨ç«™æ”»å‡»ä¸Žé˜²å¾¡</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-128213</link>
		<dc:creator>éšå¿ƒåšå®¢ &#187; Blog Archive &#187; CSRFâ€”è·¨ç«™æ”»å‡»ä¸Žé˜²å¾¡</dc:creator>
		<pubDate>Mon, 08 Mar 2010 15:39:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-128213</guid>
		<description>[...] Google GMail E-mail Hijack Technique,Â http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/ [2] XSS POST Forwarder,Â http://whiteacid.org/misc/xss_post_forwarder.php [3] CSRF [...]</description>
		<content:encoded><![CDATA[<p>[...] Google GMail E-mail Hijack Technique,Â http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/ [2] XSS POST Forwarder,Â http://whiteacid.org/misc/xss_post_forwarder.php [3] CSRF [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Consejos para proteger tu dominio &#171; clipping de internet</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-128083</link>
		<dc:creator>Consejos para proteger tu dominio &#171; clipping de internet</dc:creator>
		<pubDate>Thu, 07 Jan 2010 00:41:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-128083</guid>
		<description>[...] de algÃºn sujeto sin escrÃºpulos. Tal vez el caso mas paradigmÃ¡tico sea el de tonterias.com donde un fallo en Gmail hizo posible que cayera en manos de de quien no [...]</description>
		<content:encoded><![CDATA[<p>[...] de algÃºn sujeto sin escrÃºpulos. Tal vez el caso mas paradigmÃ¡tico sea el de tonterias.com donde un fallo en Gmail hizo posible que cayera en manos de de quien no [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ð Ñ‚Ñ‹ ÑƒÐ²ÐµÑ€ÐµÐ½ Ð² Ð±ÐµÐ·Ð¾Ð¿Ð°ÑÐ½Ð¾ÑÑ‚Ð¸ ÑÐ²Ð¾ÐµÐ³Ð¾ gmail? &#171; GCoda</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-128061</link>
		<dc:creator>Ð Ñ‚Ñ‹ ÑƒÐ²ÐµÑ€ÐµÐ½ Ð² Ð±ÐµÐ·Ð¾Ð¿Ð°ÑÐ½Ð¾ÑÑ‚Ð¸ ÑÐ²Ð¾ÐµÐ³Ð¾ gmail? &#171; GCoda</dc:creator>
		<pubDate>Sat, 19 Dec 2009 13:57:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-128061</guid>
		<description>[...] Ð¸ davidairey ÐµÐ·Ðµ Ñ€ÐµÐºÐ¾Ð¼ÐµÐ½Ð´ÑƒÑŽ Ð¿Ð¾Ñ‡Ð¸Ñ‚Ð°Ñ‚ÑŒ Ð¾ Ñ‚Ð¾Ð¼ ÐºÐ°Ðº Ð¼Ð¾Ð¶Ð½Ð¾ Ð±Ñ‹Ð»Ð¾ ÑƒÐ²ÐµÑÑ‚Ð¸ ÑÑ‰Ð¸Ðº Ð½Ð° google mail   Ð”Ð¾Ð±Ð°Ð²ÑŒ ÑÑÑ‹Ð»ÐºÑƒ Ðº [...]</description>
		<content:encoded><![CDATA[<p>[...] Ð¸ davidairey ÐµÐ·Ðµ Ñ€ÐµÐºÐ¾Ð¼ÐµÐ½Ð´ÑƒÑŽ Ð¿Ð¾Ñ‡Ð¸Ñ‚Ð°Ñ‚ÑŒ Ð¾ Ñ‚Ð¾Ð¼ ÐºÐ°Ðº Ð¼Ð¾Ð¶Ð½Ð¾ Ð±Ñ‹Ð»Ð¾ ÑƒÐ²ÐµÑÑ‚Ð¸ ÑÑ‰Ð¸Ðº Ð½Ð° google mail   Ð”Ð¾Ð±Ð°Ð²ÑŒ ÑÑÑ‹Ð»ÐºÑƒ Ðº [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tiesto</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-127843</link>
		<dc:creator>tiesto</dc:creator>
		<pubDate>Tue, 15 Sep 2009 04:37:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-127843</guid>
		<description>Love You Gmail :p</description>
		<content:encoded><![CDATA[<p>Love You Gmail :p</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How to Find if Someone is Spying your Gmail Account &#124; Technobuz</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-127664</link>
		<dc:creator>How to Find if Someone is Spying your Gmail Account &#124; Technobuz</dc:creator>
		<pubDate>Sat, 01 Aug 2009 06:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-127664</guid>
		<description>[...] See about the bug/flaw here:Google GMail E-mail Hijack Technique [...]</description>
		<content:encoded><![CDATA[<p>[...] See about the bug/flaw here:Google GMail E-mail Hijack Technique [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Los agujeros de Google &#124; Geekotic</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-127499</link>
		<dc:creator>Los agujeros de Google &#124; Geekotic</dc:creator>
		<pubDate>Wed, 17 Jun 2009 22:14:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-127499</guid>
		<description>[...] exploits y agujeros de seguridad que esta sufriendo Google actualmente. Desde un bug de Gmail que permite el reenvÃ­o de emails que cumplan determinadas condiciones al atacante hasta uno relacionado con el sistema de encuestas [...]</description>
		<content:encoded><![CDATA[<p>[...] exploits y agujeros de seguridad que esta sufriendo Google actualmente. Desde un bug de Gmail que permite el reenvÃ­o de emails que cumplan determinadas condiciones al atacante hasta uno relacionado con el sistema de encuestas [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rmadeat</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-127467</link>
		<dc:creator>rmadeat</dc:creator>
		<pubDate>Thu, 11 Jun 2009 15:33:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-127467</guid>
		<description>Quote :

Wow, lifesavers, you guys totally rock. My problem is that I think I have a total data stream process on me - from gmail, devart, facebook, google searching - everything. May also have got into or are trying to get into my ISP email. My complete digital footprint seems to have been uplifted and is being taunted back to me on various bogus sites found through combining my various identity markers in google searches.</description>
		<content:encoded><![CDATA[<p>Quote :</p>
<p>Wow, lifesavers, you guys totally rock. My problem is that I think I have a total data stream process on me &#8211; from gmail, devart, facebook, google searching &#8211; everything. May also have got into or are trying to get into my ISP email. My complete digital footprint seems to have been uplifted and is being taunted back to me on various bogus sites found through combining my various identity markers in google searches.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Backdoor Into Gmail &#171; memoirs on a rainy day</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-126225</link>
		<dc:creator>Backdoor Into Gmail &#171; memoirs on a rainy day</dc:creator>
		<pubDate>Tue, 03 Mar 2009 01:31:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-126225</guid>
		<description>[...]   Published March 3, 2009   asides , technology Tags: asides, Gmail, technology      There was a backdoor into Gmail. It’s been [...]</description>
		<content:encoded><![CDATA[<p>[...]   Published March 3, 2009   asides , technology Tags: asides, Gmail, technology      There was a backdoor into Gmail. It’s been [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/comment-page-3/#comment-125946</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Fri, 13 Feb 2009 02:50:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique#comment-125946</guid>
		<description>Wow, lifesavers, you guys totally rock.  My problem is that I think I have a total data stream process on me - from gmail, devart, facebook, google searching - everything.  May also have got into or are trying to get into my ISP email.  My complete digital footprint seems to have been uplifted and is being taunted back to me on various bogus sites found through combining my various identity markers in google searches.</description>
		<content:encoded><![CDATA[<p>Wow, lifesavers, you guys totally rock.  My problem is that I think I have a total data stream process on me &#8211; from gmail, devart, facebook, google searching &#8211; everything.  May also have got into or are trying to get into my ISP email.  My complete digital footprint seems to have been uplifted and is being taunted back to me on various bogus sites found through combining my various identity markers in google searches.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

