Gmail accounts 'wide open to exploit'

If it's not covered by one of those other categories, you should probably talk about it here. Be nice.
Post Reply
User avatar
darkvader
Site Admin
Posts: 1098
Joined: Wed Feb 19, 2003 1:17 am
Location: Knoxville
Contact:

Gmail accounts 'wide open to exploit'

Post by darkvader »

Gmail accounts 'wide open to exploit'

Article on The Register

By John Leyden
Published Friday 29th October 2004 16:50 GMT

Google's high profile webmail service, Gmail, is vulnerable to a security exploit that might allow hackers full access to a user's email account simply by knowing the user name, according to reports.

The security flaw allows full access to users' accounts, with no need of a password, Israeli news site Nana says . Using a hex-encoded XSS link, the victim's cookie file can be stolen by a hacker, who can later use it to identify himself to Gmail as the original owner of an email account, regardless of whether or not the password is subsequently changed. Following up a tip from an Israeli hacker, journos from the site confirmed the attack and verified the exploit with local security firm Aladdin Knowledge Systems.

It's unclear whether the hole has been maliciously exploited. Google has been notified of the issue and is reportedly working on a fix. No-one from the company was available to update The Register on the issue at time of going to press.
User avatar
junkie christ
Over 5000 Posts. Beware the Junkie Rant!
Posts: 5184
Joined: Wed May 07, 2003 5:11 am
Location: doomed to fail
Contact:

Post by junkie christ »

but if google really wants to flip off an answer to this
a) its in beta
b)invite only, its not exactly like users can sign up
c) free free free

they run with any of those or a mix of it... plus theres not really a EULA thats static.... so... google wont exactly get hit up for this.

but how many holes have they found in hotmail? or outlook express (mwahaahaha)? i figure google is due one big hole.

plus i still think gmail is neat, but it has some big issues, ill just add one more to my list
O(+>
Drinking makes you the same asshole your father was.
http://www.knoxnihilism.com/forum - site admin.
Prayer, Praise, Profit.
Vachy
Posts: 408
Joined: Mon Sep 29, 2003 5:46 pm
Location: Fountain City
Contact:

Post by Vachy »

I use yahoo. It works pretty good except that I can't skip lines when I write mail (any idea how to fix this?) I had an opportunity go have a gmail account, but passed. When it's out of beta and I learn a bit more about it, perhaps.
Image
Post Reply
Users browsing this forum: No registered users and 4 guests