Home :: Newsletters :: RSS Feeds :: About Us :: Advertise     
The Industry Standard News and Analysis for the Internet Economy
NEWS
METRICS
BLOGS
JOBS
EVENTS
        Internet News for Internet Business Monday, 04th of April, 2005   

  TOPICS
Technology
Media
Money
Politics
Opinion and Blogs


  Newsletter/RSS
Sign up today for the daily email newsletter:





  BLOGS
Denise Howell
JD Lasica
Esme Vos
Scott Rafer
Ross Mayfield
Doc Searls
Seth Godin
Ashlee Vance
Matt McAlister
Tom Hespos
Mark Jones
Jen Muehlbauer
Cringe Worthy
Mark Frauenfelder
Declan McCullagh
Julene Snyder
Mark Glaser
Rafat Ali
Thomas Goetz
Mike Butcher
Jimmy Guterman

>> RSS Feed



  Archive

Recent Entries:
US PlayStation Portable sales top 500,000 in two days
Yahoo to support Wikipedia (Update)
AOL starts rolling out 'Net phone service
Google intros Q&A service
Microsoft creates tools to crack child porn cases



Previous Story: Wiki startup JotSpot draws crowd for product beta
Next Story: Crackdown closed 18,000 Internet cafes in China


Google plugs hole exposing Gmail mail-boxes
By Joris Evers

Google Inc. has fixed a security flaw in its Gmail Web-based e-mail service that allowed attackers to hijack users' e-mail accounts.

"Google was recently alerted to a potential security vulnerability affecting the Gmail service. We have since fixed this vulnerability, and all current and future Gmail users are protected," Google spokesman Nathan Tyler said.

Tyler declined to discuss the nature of the problem, but a source close to Google confirmed that the flaw allowed an attacker to gain complete control over a user's account.

The problem was in the way Gmail authenticated users. An attacker could steal a so-called cookie file identifying the user by making use of a seemingly innocent link to Google's own Web site, according to a report on the Web site of the Israeli publication Nana NetLife Magazine on Thursday.

The cookie allowed an attacker to sign on to Gmail as the victim from any computer without having to enter a password. The attacker would continue to be able to access the Gmail account even if the password were changed, according to Nana NetLife, which cited an Israeli hacker named Nir Goldshlagger.

An investigation by Google found that only a handful of Gmail users were victimized, the source close to the Mountain View, California-based company said.

Google announced Gmail in April, grabbing headlines because of the massive 1G-byte storage space provided with a Gmail account. The service is still officially in beta testing and Internet users can only get accounts after receiving an invitation from a current user. Google does not disclose how many Gmail accounts it hosts.

Posted October 31, 2004 04:45 PM | TrackBack (1)




FREE Email Newsletter RSS Feeds
Sign up today for the
daily email newsletter:








    ADDITIONAL RESOURCES:
    • Find reviews of digital cameras and download the latest graphics tools from PCWorld.
    • Astonish your colleagues with the latest technology news and trends from Computerworld.
    • Digital music that matters: chart-toppers and free audio files from Playlistmag.com.
    • Catch a daily glimpse behind the forces shaping the security business from CSOonline.com.
    • In-depth look at networking products, by Network World's team of independent reviewers.
    • Top reviews, analyses & evaluation of IT products by technology experts from InfoWorld.
    • Hot tech news with links to blogs and resources around the Internet on Lockergnome.

    MORE INTERNET NEWS LINKS


Home :: Newsletters :: RSS Feeds :: About TheStandard :: Advertise    
Copyright © 2004, TheStandard.com :: Terms and Conditions :: Privacy Policy