Home » Security

Your Google Passwords can be popped if you “Remember me”

A pretty inresting post on how Google accounts like Orkut or even gmail can be popped in case you even by mistake check on Remember Me check box when you login.

Here is how thing works:

  • If user had used Remember Password feature in any computer at cybercafe or shared computer at home.
  • I can double click on text box which asks for username and select any of them. As it remembers you password it will appear there.
  • Now definitely I can not see your password this way but this is what I will do to see

Type this in address bar and hit enter

https://www.google.com/accounts/ServiceLoginBox?service=orkut&nui=
2&uilel=1&skipvpage=true&continue=https%3A%2F%2Fwww.orkut.com
%2FRedirLogin.aspx%3Fmsg%3D0%26page%3Dhttp%253A%252F%252
Fwww.orkut.com%252FHome.aspx&followup=https%3A%2F%2Fwww.orkut.com
%2FGLogin.aspx&hl=en-US’

Next Select username and again password shows up in the box in dots or *. Now type this in your address bar and hit enter and you will see the password getting displayed.

Probably its the fault on users part to use the “Remember me ” feature but I was guessing the password gets encrypted as soon as we type but no. They must be getting encrypted only when it is sent to Google servers.

This is definetly a bug and should be resolved by them. Encrypting at this level wont be difficult. You can read Atul’s post for images and much more details at Hacking social networking users account.

Tags: , , ,

Translate to EnglishÜbersetzen Sie zum Deutsch/GermanПереведите к русскому/RussianΜεταφράστε στα ελληνικά/GreekVertaal aan het Nederlands/Dutchترجمة الى العربية/Arabic中文翻译/Chinese Traditional中文翻译/Chinese Simplified한국어에게 번역하십시오/Korean日本語に翻訳しなさい /JapaneseTraduza ao Português/PortugueseTraduca ad Italiano/ItalianTraduisez au Français/FrenchTraduzca al Español/Spanish
SMS subscribe Print This Post

Posted on 22nd January 2008 by Ashish Mohta , A tech blogger who writes about solving day to day problems of people who use computer. He also writes on How to use the applications like Office, PC tips, Online tools,Browsers and more. All posts by Ashish Mohta | Connect with me @ Twitter | Linkedin | Facebook | Stumble | Need more help? Ask your Questions at our Support Center




2 Comments »

  • Rajesh said:

    Encryptions never happen on the client side and they can only happen on the server side…this is not a bug….Why should encryption happen on the client side? what purpose does it serve?

    however HTTPS is a secured way of connecting to GMAIL as i posted recently..

  • Ashfame said:

    Hey!
    I think something is missing after this line.

    Now type this in your address bar and hit enter and you will see the password getting displayed.

Leave your response!

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>