Welcome Guest ( Log In | Register )

  Recent Software News
Phel Trojan targets Windows flaw
Cabir cell phone threat worsens
19 LingvoSoft dictionaries for Wind...
Microsoft posts critical configurat...
Apple ships Mac OS X update
  Recent Gaming News
Electronic Arts to buy into Ubi Sof...
Halo 2, San Andreas key drivers of ...
Sony Says All Systems Go for PSP La...
Nvidia to work on PlayStation 3 chi...
New Command & Conquer Game Unveiled
  Recent Reviews
 · CoolerMaster Aerogate 3 A...
 · CoolerMaster AquaGate Wat...
 · OCZ Copper BGA Ramsinks
 · Mapower Warps Portable 3....
 · Vantec - PCI & RAM Slot P...
  Recent Forum Posts
How to enable use of nvidia dr...
Windows XP Sp2 Problems
Leadtek A350XT TDH and overclo...
FX5900U vs 9800Pro
Google Gmail Invites
  Announcement

Welcome to AusPCWorld - Australia's Leading PC Technology News & Reviews site.



> AusPCWorld > Tech News > Gmail accounts 'wide open to exploit' - report






   
Gmail accounts 'wide open to exploit' - report
Posted by mitchy_g on 01 Nov 2004 - 11:38 0 comments
Previous Post | Tech News | Next Post
 
Google's high profile webmail service, Gmail, is vulnerable to a security exploit that might allow hackers full access to a user's email account simply by knowing the user name, according to reports.

The security flaw allows full access to users' accounts, with no need of a password, Israeli news site Nana says . Using a hex-encoded XSS link, the victim's cookie file can be stolen by a hacker, who can later use it to identify himself to Gmail as the original owner of an email account, regardless of whether or not the password is subsequently changed. Following up a tip from an Israeli hacker, journos from the site confirmed the attack and verified the exploit with local security firm Aladdin Knowledge Systems.

It's unclear whether the hole has been maliciously exploited. Google has been notified of the issue and is reportedly working on a fix. No-one from the company was available to update The Register on the issue at time of going to press.

News source: The Register



There are 0 additional comments, Post a comment | View printable post | Open/Close All Comments


Add A new comment
Name: (Register)
Email: (optional)
Quick HTML: (help)
  Close current tag   Standard Mode
  Close all tags   Enhanced Mode
Comment:


Smilies
(help)
Parse URL's: (will automatically add [url] [/url] round the web addresses in your comment)