28-09-2007, 03:56 AM
|
#3 (permalink)
|
|
GaurishSharma.com
Join Date: May 2005
Location: Jaipur
Posts: 4,116
|
Re: Gmail flaw allows attackers to steal messages
Quote:
In the example, the attacker writes a filter, which simply looks for e-mails with attachments and forwards them to an e-mail of their choice," Petkov said. "This filter will automatically transfer all e-mails matching the rule
Keep in mind that future e-mails will be forwarded as well. The attack will remain present for as long as the victim has the filter within their filter list, even if the initial vulnerability, which was the cause of the injection, is fixed by Google," he added.
Google confirmed the vulnerability and said it is working on a fix, but did not give a timetable for patching Gmail, saying only that "we expect [it] to be implemented shortly."
|
Given in provided link itself
|
|
|