Version: 2008

Comments on: Google fixes 'minor' Gmail flaw

Flaw first flagged by a teenage blogger could allow the execution of script code, possibly resulting in account hijacks.

Add a Comment (Log in or register) (7 Comments)
  • prev
  • 1
  • next
14?
by oo7evan March 2, 2006 4:59 PM PST
Why is a 14 year old sending java script around?
Reply to this comment
..why not?
by assman March 2, 2006 5:17 PM PST
when i was 14 i began learning javascript. not exactly sure why he was sending it from one email account to the other though. it makes more sense that he was trying to find a flaw in the first place.

i can already imagine what the flaw was. an email with javascript code most likely was mistakingly used in the browser while inside the email instead of converting the code to unalterable text for display.
View reply
14 years olds are more brilliant than you think
by March 3, 2006 10:08 AM PST
Because they can. Remember when you were 14? :)

Kids are getting smarter and smarter these days, contrary to what the media would have you believe. One 14-year I worked with a few years ago had attained full Novell certification(Certified Novell Engineer)- on top of doing his regular high school curriculum. Yup, wrote and passed all the relevant Novell Netware exams. He became the de-facto Network Administrator for the school. Too bad he easily succumbed to peer pressure, and granted all his buddies admin privileges too.

And his peers were all 14-15 year old Linux hackers. A vendor plugged in their unix firewall appliance at the high school, and minutes later it was hacked to bits.

Just imagine - if they can do all this before even hitting puberty - how much more could they do years down the road?
View reply
Google mailing list service 'groups'
by n3td3v March 3, 2006 4:37 AM PST
I disclosed insecure script handling on Google's service.

The flaw was able to harvest millions of e-mail addresses.

The flaw was able to hi-jack entire groups

Compromise owner and moderator e-mail accounts

Leave a mailicious owner and moderator account in thousands of groups

Was disclosed to the major mailing lists in December 2005 as "Google is vulnerable from XSS attack"

50 to 80 days later, still was no fix.

Put the flaw on Digg.com as "Unpatched: Google attack vector" and the flaw was finally fixed, weeks after that.

Major delay for a flaw which is able to cause global consequence to spam and phishing in months and years to come.

Maybe the entire list of e-mail addresses should be put up on eBay?

Your corporate and consumer e-mail spam and phishing coming at you due to a javascript flaw thats "minor".

I wonder how much money will be made from the sale? eBay will be forced to pull the sale, but at least the timely sale will get media attention.

Regards,

n3td3v

The harvest is still continuing to this day because of the malicious owner and moderator accounts left on thousands of existing groups, which pick-up new members as they join a group.

Google Groups owned? You decide.
Reply to this comment
Frightening
by scriptki77y March 4, 2006 1:38 PM PST
Sometimes, your comments are frightening to me. While I do realize that they are entirely too realistic...I'm not sure how to put it...

Let me just say, I am glad that I do not use Google Groups.
(7 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement