The Confused Deputy and the Domain Hijacker
IEEE Security & PrivacyPublished 1 January 2008
Dave Ahmad
Citations9
SJR quartileQ1
SJR score0.43
SNIP1.10
Generate an AI Snapshot to get a quick, structured summary of this paper.
Study Snapshot
ObjectiveStudy objective
MethodsResearch methodology
PopulationPopulation studied
Sample sizeSample sizes
OutcomesStudy outcomes here
ResultsStudy results comes here
LimitationsResearch study limitations comes here
A concise AI-generated summary of the paper will appear here once you click Generate AI Snapshot.
TL;DR
The Gmail vulnerability allowed unauthorized parties to add custom mail filters to target Gmail accounts with the only requirement was that the target users visit a Web site with malicious content while signed into Gmail.
Abstract
The author discusses a common Gmail vulnerability, cross-site request forgery. During the time a user is authenticated to an online application, such as Web mail, the user's browser can be coerced into making authenticated requests to the application on a third party's behalf. Using that, it's quite simple to hijack domains that don't belong to you.
Keywords
Computer Science
