login

The Confused Deputy and the Domain Hijacker

IEEE Security & PrivacyPublished 1 January 2008
Dave Ahmad
Citations9
SJR quartileQ1
SJR score0.43
SNIP1.10

TL;DR

The Gmail vulnerability allowed unauthorized parties to add custom mail filters to target Gmail accounts with the only requirement was that the target users visit a Web site with malicious content while signed into Gmail.

Abstract

The author discusses a common Gmail vulnerability, cross-site request forgery. During the time a user is authenticated to an online application, such as Web mail, the user's browser can be coerced into making authenticated requests to the application on a third party's behalf. Using that, it's quite simple to hijack domains that don't belong to you.

Keywords

Computer Science