Gmail reveals secrets to hackers

By
Follow google news

People sending emails to Gmail accounts may find they reveal more than they bargained for. A bug within Google mail service allows hackers to reveal details of other users’ personal emails, and even their account passwords.

UNIX firm HBX Networks stumbled across the flaw whilst working on a "hacker-friendly" shell service. In altering the "From" part of the address bar technicians for HBX found that HTML code was revealed within the "Reply-to" field.


"The result is a compromise of the privacy of communications over Gmail," said an HBX spokesman on its website. "Many people rely on Gmail heavily, and many users are forced to communicate with Gmail users because of this resilience."

A lot of the information revealed by the flaw is spam, but there are notable exceptions. One example, detailed in HBX's report, highlights an account password.

"We are aware of the problem and we are looking into it," said a Google spokeswoman.

Late last month virus writers created a the Santy worm that used Google's powerful search engine to search for vulnerable websites. Earlier in December SC reported on how Google's desktop search engine could create security problems for customers using SSL VPNs.

dump.hbx.us/gmail_bug

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

FBI remotely patched privately-owned routers to evict Russian GRU spies

FBI remotely patched privately-owned routers to evict Russian GRU spies

Dead cars tell tales by storing data that's never wiped

Dead cars tell tales by storing data that's never wiped

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

AI-boosted hacks with Anthropic’s Mythos could have dire consequences for banks

AI-boosted hacks with Anthropic’s Mythos could have dire consequences for banks

Log In

  |  Forgot your password?