Nov
Gmail Security Flaw Proof of Concept
Is it possible for someone to create a malicious filter without having access to your Gmail username and password? No, however, they can force you to create the filter without your knowledge.
The blogosphere is buzzing about a Gmail Security Flaw that has caused some people to lose their domain names registered through GoDaddy.
To understand how this exploit works let me first explain how I would carry it out (if I were a blackhat). Then we can move on and explain the exploit in detail.
Brandon has written an informative article on this exploit over at geekcondition.com.
If you use Gmail, have filters set up and have a domain registered with GoDaddy you should read the full article. Then I’d recommend you immediately change hosts. My dislike of GoDaddy is documented elsewhere.



