Press CTRL-D to bookmark us
Welcome Guest Login / Register / Members
Search in  
Top Submit newsSubscribe
Communication | Computer Crime | Digital Audio, Video, Photo | General News | Hardware | Internet | Mobile | PDA | Security | Software | Vulnerability |


Previous articleBack to news listNext article
 

 Sponsored links

Want to become one of our authors and see your work published on ALLSeek.iNFO ?
 
 Google plugs hole exposing Gmail mail-boxes
Categorie: Vulnerability
Posted: 2004-12-02 by ReCall
Views: 391
Source: Click here
 
Current Rating: Not rated
Poor Best
 Details
Google plugs hole exposing Gmail mail-boxes


Google has fixed a security flaw in its Gmail web-based e-mail service that allowed attackers to hijack users' e-mail accounts.

"Google was recently alerted to a potential security vulnerability affecting the Gmail service. We have since fixed this vulnerability, and all current and future Gmail users are protected," said Google spokesman Nathan Tyler.

Tyler declined to discuss the nature of the problem, but a source close to Google confirmed that the flaw allowed an attacker to gain complete control over a user's account.

The problem was in the way Gmail authenticated users. An attacker could steal a so-called cookie file identifying the user by making use of a seemingly innocent link to Google's own website, according to a report on the website of the Israeli publication Nana NetLife Magazine.

The cookie allowed an attacker to sign on to Gmail as the victim from any computer without having to enter a password. The attacker would continue to be able to access the Gmail account even if the password were changed, according to Nana NetLife, which cited an Israeli hacker named Nir Goldshlagger.

An investigation by Google found that only a handful of Gmail users were victimised, the source close to the company said.

Google announced Gmail in April, grabbing headlines because of the massive 1Gbyte storage space provided with a Gmail account. The service is still officially in beta testing and internet users can only get accounts after receiving an invitation from a current user. Google does not disclose how many Gmail accounts it hosts.
 
Syndication
Permalink Email this

The URI to TrackBack this entry is:
http://allseek.info/news/trackback.php?id=1148

User comments (post your comments here)

Only registerd members can post comments and articles
 

Previous articleBack to news listNext article
 



InterJOB.su

SpyLOG Page Rank Checker
LAST QUERIES