Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 11-05-2008, 10:27 PM   #1 (permalink)
left this forum longback
 
praka123's Avatar
 
Join Date: Sep 2005
Location: -
Posts: 7,536
Post Security flaw turns Gmail into open-relay server


Security flaw turns Gmail into open-relay server
By Joel Hruska Published: May 10, 2008 - 01:15PM CT

A recently-discovered flaw in Gmail is capable of turning Google's e-mail service into a highly effective spam machine. According to the Information Security Research Team (INSERT), Gmail is susceptible to a man-in-the-middle attack that allows a spammer to send thousands of bulk e-mails through Google's SMTP service without fear of detection. This attack bypasses both Google's identity fraud protection mechanisms and the current 500-address limit on bulk e-mail.

A flaw in Gmail that allows spammers to send a potentially unlimited number of messages is definitely a problem, but there's another, external factor that could exacerbate any potential spam attack. As the volume of spam has risen—it currently accounts for 95 percent of all e-mail traffic—many e-mail providers have adopted whitelists and blacklists as a first line of defense against the flood. An e-mail from johdoe@awinnerisyou.com (or the corresponding IP address block) may be automatically blocked by any given e-mail service, while an e-mail from a trusted, authenticated source such as Gmail is automatically allowed through the gateway. E-mail providers regularly use multi-level filtering services, any of which might detect that the forged Gmail missive is actually spam, but the message has cleared a substantial hurdle that would have otherwise barred it from delivery.

E-mail that originates from Google, it seems, is particularly well-regarded by both Yahoo and Hotmail. The INSERT team tested the degree of trust between the three major e-mail providers by sending spam messages to Yahoo and Hotmail using two sources. In the first test, messages were sent from personal systems whose IP addresses had been blacklisted by Yahoo and Hotmail. The second test consisted of sending the exact same message via the Gmail flaw that INSERT discovered.

The difference was significant. E-mail sent to Yahoo and Hotmail from a blacklisted IP didn't even necessarily reach the account's spam box, while forged e-mail sent via Gmail always arrived in the intended account's inbox. The goal here is not to condemn trusted-source filtering as bad, but to emphasize how a security flaw in a single product or service can ripple through an ecosystem. Google will likely act quickly to close this particular loophole, but Yahoo and Hotmail might want to read their Russian proverbs a little more closely. doveryai, no proveryai (Trust, but Verify) remains an eternally good idea.



http://arstechnica.com/news.ars/post...ay-server.html
__________________
left this forum long back.Admin Can Delete this Account and posts Permanantly.Thank You
Get GNU/Linux - http://getgnulinux.org
praka123 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 12-05-2008, 12:44 AM   #2 (permalink)
Somebody stop me...
 
Join Date: May 2008
Location: Paris
Posts: 225
Default Re: Security flaw turns Gmail into open-relay server

I am not sure but i have read story somewere about how gmail account was hacked and thn asked original owner to pay money to give it back..
swordfish is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Apple Mail Security Flaw Reborn in Leopard CadCrazy Technology News 5 22-11-2007 01:50 PM
Gmail flaw allows attackers to steal messages ankitsagwekar Technology News 7 30-09-2007 08:10 PM
Security flaw in vista! Anindya Technology News 4 08-02-2007 07:00 AM
Free SMTP relay server Hulo QnA (read only) 3 22-07-2005 11:10 AM
Latest Firefox reintroduces 7-year-old security flaw ferrarif50 Software Q&A 1 13-06-2005 04:12 PM

 
Latest Threads
- by chris
- by abhidev
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 05:44 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2