Automatically Hack Gmail Accounts

Recently a tool has been presented in Defcon hackers’ conference in Las Vegas, that automatically steals the IDs of non encrypted sessions and this tool is very useful for breaking Gmail user ID. When Users login into Gmail account, Gmail Server sends Cookie (A text file) to your browser. This file helps Gmail server to know that you are authenticated. This Cookie will log-in you in for 2 week unless you press sign-out or delete the Cookie. Even though when you authenticated using SSL, after that you are also not secure because the result return by the Gmail server is unencrypted connection.

Every time you request anything from the Gmail server like an image, your browser sends this Cookie file to Gmail server and any attacker can easily get this Cookie file by applying any network sniffer tool. After this attacker get your Gmail session ID and using this Session ID attacker can easily logged in your Gmail account without the need of any Username and Password. People using Gmail from public places, cybercafé and public wireless hotspots are more likely get rid by this type of attacks.

Always use https://mail.google.com because this will access the SSL version of Gmail. it will be persistent over your entire session and not only during authentication.

Tags:

Gmail Contact Manager Updated

Gmail Contact Manager Updated Gmail automatically contact adding feature some times these contacts can lead to too much address book clutter. One of the advantage of auto adding contact list is that Gmail users don’t have to worry about to add contacts manually but this week Gmail team come up with a new concept of "My Contacts" and "Suggested Contacts." 

Gmail Contact Manager Updated

My Contacts contains the contacts you explicitly put in your address book (via manual entry, import or sync) as well as any address you’ve emailed a lot (we’re using five or more times as the threshold for now).

Suggested Contacts is where Gmail puts its auto-created contacts. By default, Suggested Contacts you email frequently are automatically added to My Contacts, but for those of you who prefer tighter control of your address books, you can choose to disable usage-based addition of contacts to My Contacts (see the checkbox in the screenshot above). Once you do this, no matter how many times you email an auto-added email address it won’t move to My Contacts.

Source : Gmail Blog

Tags: