Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 01-10-2007, 12:35 PM   #1 (permalink)
ax3
Cool as a CUCUMBAR ! ! !
 
ax3's Avatar
 
Join Date: Dec 2003
Posts: 5,052
Default Google fixes Gmail 'ethical hacker' vulnerability


Three days after ethical hacker Petko Petkov announced his discovery of a cross-site scripting vulnerability in Gmail, Google says it has fixed the problem.


"We worked quickly to address the recently reported vulnerability, and we have rolled out a fix," a Google Australia spokesperson told ZDNet Australia today.


The vulnerability discovered by Petkov, who posted his findings at the GNUCitizen Web site, could potentially allow a attacker to seize control of session cookies if a user clicked on a malicious link while logged into their account.


Under the scenario, an attacker could siphon e-mails from the hacked account to a separate POP account, Chris Gatford, from penetration-testing company Pure Hacking, explained to ZDNet Australia on Wednesday.


"If someone picks up on this before Google fixes it -- or if someone knew of the vulnerability before this guy published it -- this could be very damaging to Gmail users," Gatford said.


However, Google's spokesperson said the search giant had not received any reports of the vulnerability being exploited, and added: "Google takes the security of our users' information very seriously."


Pure Hacking's Gatford said cross-site scripting vulnerabilities are gaining popularity amongst attackers and that many organisations -- including Australian Federal Government departments -- are overlooking the problem.


"In the last year or so, [cross-site scripting vulnerabilities] have been used by attackers to grab cookie values and therefore gain access to normally password protected sites," said Gatford.


Source : http://www.zdnetindia.com/
__________________
... W H O T ...
ax3 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 01-10-2007, 12:51 PM   #2 (permalink)
Human Spambot
 
Cool G5's Avatar
 
Join Date: Aug 2006
Location: Aamchi Mumbai !!!
Posts: 4,227
Default Re: Google fixes Gmail 'ethical hacker' vulnerability

Good work.
__________________
ShutterTux - Photography, Linux & Life! : http://shuttertux.wordpress.com
Cool G5 is offline  
Old 01-10-2007, 12:52 PM   #3 (permalink)
AJJU
 
azzu's Avatar
 
Join Date: Aug 2006
Location: hYdErAbAd
Posts: 2,429
Default Re: Google fixes Gmail 'ethical hacker' vulnerability

nice info
__________________
I love and Live to Design
azzu is offline  
Old 01-10-2007, 01:02 PM   #4 (permalink)
Human Spambot
 
Join Date: Jan 2007
Location: Lat 28.38°N , Longt 77.13°E
Posts: 2,431
Default Re: Google fixes Gmail 'ethical hacker' vulnerability

Good news
ThinkFree is offline  
Old 01-10-2007, 01:23 PM   #5 (permalink)
The Thread Killer >:)
 
phreak0ut's Avatar
 
Join Date: Apr 2006
Location: Bangalore
Posts: 1,185
Default Re: Google fixes Gmail 'ethical hacker' vulnerability

Very cool of both Google and Petkov
__________________
Want to make this world a better place? Then, start seeding and don't be just a leecher :)
phreak0ut is offline  
Old 01-10-2007, 01:39 PM   #6 (permalink)
ax3
Cool as a CUCUMBAR ! ! !
 
ax3's Avatar
 
Join Date: Dec 2003
Posts: 5,052
Default Re: Google fixes Gmail 'ethical hacker' vulnerability

thanx .... just found it out on THAT site & thought of sharing with u all ....
__________________
... W H O T ...
ax3 is offline  
Old 01-10-2007, 02:08 PM   #7 (permalink)
GaurishSharma.com
 
gary4gar's Avatar
 
Join Date: May 2005
Location: Jaipur
Posts: 4,116
Default Re: Google fixes Gmail 'ethical hacker' vulnerability

WOw 3 days nice & fast
thanks for informing
gary4gar is offline  
Old 01-10-2007, 02:14 PM   #8 (permalink)
Noobie Pro
 
alsiladka's Avatar
 
Join Date: Jan 2007
Location: Here, there, everywhere
Posts: 1,062
Default Re: Google fixes Gmail 'ethical hacker' vulnerability

Pretty quick response time from google. Impressed.
But i have seen, this is not the firm time a flaw has been found in Gmail's codes.
__________________
www.twitter.com/alsiladka
alsiladka is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Opera releases v9.21: Fixes highly critical vulnerability eddie Technology News 2 23-05-2007 07:46 PM
14 year old discovers Gmail vulnerability shwetanshu Technology News 5 08-03-2006 07:21 AM

 
Latest Threads
- by chris
- by abhidev
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 03:52 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2