Archive for November 23rd, 2008

23
Nov

Gmail Security Flaw Proof of Concept

Is it possible for someone to create a malicious filter without having access to your Gmail username and password? No, however, they can force you to create the filter without your knowledge.

The blogosphere is buzzing about a Gmail Security Flaw that has caused some people to lose their domain names registered through GoDaddy.

To understand how this exploit works let me first explain how I would carry it out (if I were a blackhat). Then we can move on and explain the exploit in detail.

Brandon has written an informative article on this exploit over at geekcondition.com.

If you use Gmail, have filters set up and have a domain registered with GoDaddy you should read the full article. Then I’d recommend you immediately change hosts. My dislike of GoDaddy is documented elsewhere.

Sign-up for My Newsletter
Every month you'll be informed, challenged and entertained
Name:
Email:
 
Your email address will never be shared or sold.
Powered by Optin Form Adder
Print