Collected research
Gmail - Google Docs Cookie Hijacking through PDF Repurposing
A PDF mailed to a victim is rendered harmlessly by the Google Docs viewer, but choosing print converts it back to its original form and opens it in the browser through the Adobe plugin. Acro JS then runs with an interface to the Google domain, letting the attacker read Gmail and Google Docs cookies. Disclosed to Google on 5 May 2009 and patched by 9 May.
Record
- Researcher
- Aditya K Sood
- Published by
- secniche.org
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .