Skip to content

Biting the hand that feeds IT

The Register ®


Related Whitepapers

[Print][Mobile][Alerts]

Gmail accounts 'wide open to exploit' - report

Cookie monster bites web mail service

Published Friday 29th October 2004 16:50 GMT

Google's high profile webmail service, Gmail, is vulnerable to a security exploit that might allow hackers full access to a user's email account simply by knowing the user name, according to reports.

The security flaw allows full access to users' accounts, with no need of a password, Israeli news site Nana says . Using a hex-encoded XSS link, the victim's cookie file can be stolen by a hacker, who can later use it to identify himself to Gmail as the original owner of an email account, regardless of whether or not the password is subsequently changed. Following up a tip from an Israeli hacker, journos from the site confirmed the attack and verified the exploit with local security firm Aladdin Knowledge Systems.

It's unclear whether the hole has been maliciously exploited. Google has been notified of the issue and is reportedly working on a fix. No-one from the company was available to update The Register on the issue at time of going to press. ®

Related stories

Google finally fixes Desktop security vuln
Google Desktop privacy branded 'unacceptable'
Google's Gmail: spook heaven?
California votes for Google mail safeguards
Yahoo! and Google escalate portal wars

Track this type of story as a custom Atom/RSS feed or by email.
Previous Article Next Article
whitepaper title

How IT Management Can "Green" the Data Center

This Gartner research provides managers with an outline of the trends affecting datacenters and offers strategies with which to address these changes..
whitepaper title

Gartner Paper: US Data Centers

U.S. enterprise data centers face considerable space and energy constraints over the next few years. Download this free independent report to read more..
Whitepapers

Top 20 storiesAll The Week’s HeadlinesArchiveSearch