View Single Post
Old 28-09-2007, 03:56 AM   #3 (permalink)
gary4gar
GaurishSharma.com
 
gary4gar's Avatar
 
Join Date: May 2005
Location: Jaipur
Posts: 4,116
Default Re: Gmail flaw allows attackers to steal messages

Quote:
In the example, the attacker writes a filter, which simply looks for e-mails with attachments and forwards them to an e-mail of their choice," Petkov said. "This filter will automatically transfer all e-mails matching the rule

Keep in mind that future e-mails will be forwarded as well. The attack will remain present for as long as the victim has the filter within their filter list, even if the initial vulnerability, which was the cause of the injection, is fixed by Google," he added.

Google confirmed the vulnerability and said it is working on a fix, but did not give a timetable for patching Gmail, saying only that "we expect [it] to be implemented shortly."
Given in provided link itself
gary4gar is offline