Gmail (aka Google Mail) and secure cookies
Gmail (aka Google Mail) and secure cookies
I added google.com to the list for "Force encryption for all cookies set over HTTPS by the following sites". However, even though I only log in over the https interface, one of the cookies I receive is still insecure, according to CS Lite. Additionally, even when I visit one of Google's unencrypted search pages, Google still sees me as logged in.
Why?
Why?
Mozilla/5.0 Gecko/20070713 Firefox/2.0.0.0
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: Gmail (aka Google Mail) and secure cookies
Did you tick the "Automatic secure cookie management" checkbox?
Also, are you sure the insecure cookie is from gmail.google.com and not from google.com?
Also, are you sure the insecure cookie is from gmail.google.com and not from google.com?
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)
Re: Gmail (aka Google Mail) and secure cookies
Yes, the box is ticked.Giorgio Maone wrote:Did you tick the "Automatic secure cookie management" checkbox?
It is a google.com cookie, but I placed both google.com and mail.google.com on the force secure cookies list.Giorgio Maone wrote:Also, are you sure the insecure cookie is from gmail.google.com and not from google.com?
Also, I did not temporarily allow google.com to put cookies on my computer, using CS Lite, until I reached the https login page, so it was not a pre-existing cookie. And apparently the single unsecure cookie was enough for Google to recognise me even on the non-https search page.
Mozilla/5.0 Gecko/20070713 Firefox/2.0.0.0
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: Gmail (aka Google Mail) and secure cookies
May I know the name of the cookie? I've got some suspects...
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)
Re: Gmail (aka Google Mail) and secure cookies
Name: SIDGiorgio Maone wrote:May I know the name of the cookie? I've got some suspects...
Domain: .google.com
Path: /
Secure: No
Expiration: Session
GAUSR and LSID (from HOST: http://www.google.com) are both marked as secure, as is everything from mail.google.com.
Mozilla/5.0 Gecko/20070713 Firefox/2.0.0.0
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: Gmail (aka Google Mail) and secure cookies
SID is set by http://www.google.com, which you're not enforcing HTTPS cookies on (are you?)
Just add http://www.google.com or even better *.google.com (beware, though, that some Google services which are not HTTPS enabled might cease to work).
Just add http://www.google.com or even better *.google.com (beware, though, that some Google services which are not HTTPS enabled might cease to work).
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)
Re: Gmail (aka Google Mail) and secure cookies
I had the following on the list:Giorgio Maone wrote:SID is set by http://www.google.com, which you're not enforcing HTTPS cookies on (are you?)
Just add http://www.google.com or even better *.google.com (beware, though, that some Google services which are not HTTPS enabled might cease to work).
google.com
mail.google.com
(No wildcard characters.)
I added the wildcard character, but now I can't login at all.
Mozilla/5.0 Gecko/20070713 Firefox/2.0.0.0
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: Gmail (aka Google Mail) and secure cookies
Well, I told you preventing that cookie from being set could break something.
However, you probably don't need this.
Just try to delete the secure cookies and check if you can still login. If you cannot, you're safe.
However, you probably don't need this.
Just try to delete the secure cookies and check if you can still login. If you cannot, you're safe.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)
Re: Gmail (aka Google Mail) and secure cookies
You are right.Giorgio Maone wrote:Well, I told you preventing that cookie from being set could break something.
However, you probably don't need this.
Just try to delete the secure cookies and check if you can still login. If you cannot, you're safe.
The insecure cookie seems to be insufficient to get into Google Mail with. It looks like all an attacker could do with the insecure cookie is impersonate me while searching Google and look at my Web History, which is empty because I don't let Google run scripts. So I suppose someone could frame me by searching for illegal material with my cookie, but at least my mail can't be compromised that way.
Mozilla/5.0 Gecko/20070713 Firefox/2.0.0.0
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3369
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: Gmail (aka Google Mail) and secure cookies
I was using Gmail through the website today and it logged me in and then when I changed folder, it pops up saying that it appears you have logged out or someone else has logged on to this machine, so you need to log back in and takes me away to the login page. I was pissed and so tried to log back in and this time it just sits on that loading page and bar goes to 100 and it just sits there doing abso-freakin-lutely nothing. Whatever the problem was, is back.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11