A 14 year old boy known to the world as Antony has found a Vulnerability in Gmail.
The Vulnerability is that,
"the javascriptcode present in the message will run if it is withing the preview of the message".
This vulnerability will lead the hackers to access ones Inbox and execute the code that can stel information like Email Ids or important details from your mails.
The tester has found this vulnerability when he sent a mail containing a javascript code, from his Yahoo ID to GMail.
This Vulnerability is filtered out when a mail containing the javascript code from one GMail ID to another GMail ID.
Read more about this vulnerability from the Finder's site by Clicking here.
| |
|
Welcome to KnowledgeSutra - Dear Guest | |
Vulnerability In Gmail
Started by delivi, Mar 02 2006 01:19 PM
8 replies to this topic
#2
Posted 03 March 2006 - 05:02 PM
No, wonder the original post in the blogspot has so many comments(49). At one point of time most of the email services have had complaints from users, but the good thing about them is that they have always been able to fix the problems.
Let's hope Google Gmail to come out with the same result. I have actually enjoyed much about this awesome service and approach to email by Google.
Let's hope Google Gmail to come out with the same result. I have actually enjoyed much about this awesome service and approach to email by Google.
#4
Posted 03 March 2006 - 05:28 PM
Wow. Thy better come up with a nother code or make it fool proof. That is dangerous and does place google at some liability. Of course, I don't keep anything important in my account anyway, but still, the thought of it will irk me now. Thanks a lot Delivi. Oh well.
What they need is a way to filter out the dangerous code. Maybe re-write gmail's code that it uses. I don't know, just so they get it fixed.
What they need is a way to filter out the dangerous code. Maybe re-write gmail's code that it uses. I don't know, just so they get it fixed.
#5
Posted 03 March 2006 - 07:23 PM
Looks fairly non-trivial, but hopefully shouldn't be a problem for the GMail team to get it fixed. Technically, one shouldn't be surprised - after all GMail is in Beta - that is the you've-been-warned phase, so... but I'm a bit worried because GMail has kinda grown on me now and I imagined it was this perfect system, *grin*
Reply to this topic

1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users














