Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > NZ Computing > Gmail exploit

Reply
Thread Tools

Gmail exploit

 
 
PseUDO
Guest
Posts: n/a
 
      10-30-2004
Google's high profile webmail service, Gmail, is vulnerable to a
security exploit that might allow hackers full access to a user's email
account simply by knowing the user name, according to reports. The
security flaw allows full access to users' accounts, with no need of a
password, Israeli news site Nana says.

Using a hex-encoded XSS link, the victim's cookie file can be stolen by
a hacker, who can later use it to identify himself to Gmail as the
original owner of an email account, regardless of whether or not the
password is subsequently changed. Following up a tip from an Israeli
hacker, journos from the site confirmed the attack and verified the
exploit with local security firm Aladdin Knowledge Systems.

From neowin today.

PseUDO
 
Reply With Quote
 
 
 
 
Ripping Silk
Guest
Posts: n/a
 
      10-30-2004
PseUDO wrote:
> Google's high profile webmail service, Gmail, is vulnerable to a
> security exploit that might allow hackers full access to a user's email
> account simply by knowing the user name, according to reports. The
> security flaw allows full access to users' accounts, with no need of a
> password, Israeli news site Nana says.
>
> Using a hex-encoded XSS link, the victim's cookie file can be stolen by
> a hacker, who can later use it to identify himself to Gmail as the
> original owner of an email account, regardless of whether or not the
> password is subsequently changed. Following up a tip from an Israeli
> hacker, journos from the site confirmed the attack and verified the
> exploit with local security firm Aladdin Knowledge Systems.
>
> From neowin today.
>
> PseUDO


been fixed
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Accessing GMail account from GMail Groups Ramkumar Computer Support 2 09-25-2005 09:21 AM
gmail blocks .rar files from non-gmail address kritaly Computer Support 3 08-18-2005 12:00 AM
6 gmail accounts available, post your email here or to gmail@thing.dyndns.org thing NZ Computing 6 12-01-2004 11:40 PM
Google GMail exploit Locke Nash Cole Computer Security 0 10-30-2004 12:04 AM
Re: IOS exploit: please disclose vehicle, not mechanism jankemi(remove) Cisco 16 07-25-2003 05:16 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57