iTnews

Gmail reveals secrets to hackers

By David Quainton on Jan 13, 2005 12:10PM

People sending emails to Gmail accounts may find they reveal more than they bargained for. A bug within Google mail service allows hackers to reveal details of other users’ personal emails, and even their account passwords.

UNIX firm HBX Networks stumbled across the flaw whilst working on a "hacker-friendly" shell service. In altering the "From" part of the address bar technicians for HBX found that HTML code was revealed within the "Reply-to" field.

"The result is a compromise of the privacy of communications over Gmail," said an HBX spokesman on its website. "Many people rely on Gmail heavily, and many users are forced to communicate with Gmail users because of this resilience."

A lot of the information revealed by the flaw is spam, but there are notable exceptions. One example, detailed in HBX's report, highlights an account password.

"We are aware of the problem and we are looking into it," said a Google spokeswoman.

Late last month virus writers created a the Santy worm that used Google's powerful search engine to search for vulnerable websites. Earlier in December SC reported on how Google's desktop search engine could create security problems for customers using SSL VPNs.

dump.hbx.us/gmail_bug

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
gmailhackersrevealssecretssecurityto

Partner Content

Vast majority of surveyed firms still rely on password authentication
Promoted Content Vast majority of surveyed firms still rely on password authentication
Alienated from your own data? You’re not alone
Promoted Content Alienated from your own data? You’re not alone
Teaching tech teams every step of implementing a machine learning project
Promoted Content Teaching tech teams every step of implementing a machine learning project
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • 11th Annual Fraud Prevention Summit 2022
  • IoT Impact Conference
  • Cyber Security for Government Summit
By David Quainton
Jan 13 2005
12:10PM
0 Comments

Related Articles

  • Federal Court puts cyber security onus on financial services firms
  • US says advanced hackers can hijack critical infrastructure
  • US and European partners take down hacker website RaidForums
  • British police probing hackers Lapsus$ say 2 teenagers charged
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Kmart Australia stands up consent-as-a-service platform

Kmart Australia stands up consent-as-a-service platform

NSW digital driver's licences 'easily forgeable'

NSW digital driver's licences 'easily forgeable'

Kmart Australia re-platforms ecommerce site to AWS

Kmart Australia re-platforms ecommerce site to AWS

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

Digital Nation

As NFTs gain traction, businesses start taking early bets
As NFTs gain traction, businesses start taking early bets
The other ‘CTO’: The emerging role of the chief transformation officer
The other ‘CTO’: The emerging role of the chief transformation officer
COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
Metaverse hype will transition into new business models by mid decade: Gartner
Metaverse hype will transition into new business models by mid decade: Gartner
Case Study: PlayHQ leverages graph technologies for sports administration
Case Study: PlayHQ leverages graph technologies for sports administration
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.