PDA

View Full Version : 14 year old discovers Gmail vulnerability



tesco
03-04-2006, 04:38 PM
In a blog posting on blogspot (http://ph3rny.blogspot.com/2006/03/vulnerability-in-gmail.html) a 14 year old kid named Anthony has discovered a Javascript Gmail vulnerability.

Anthony wrote "Apparently javascript will run if it is within the preview of the message" meaning that hackers could grab email addresses or possibly steal cookies and compromise Google accounts. It's surprising that this vulnerability existed and who knows how long this has been a hole.

According to Anthony the Javascript he sent to himself was from a Yahoo account, emailing from Gmail to Gmail accounts filters the code out.

24 hours after Anthony discovered the issue Google have now fixed the problem but have not issued a statement regarding this latest privacy slip up.

:source: Source: Neowin.net (http://www.neowin.net/index.php?act=view&id=32435)
:view: View: Anthony's Blog (http://ph3rny.blogspot.com/2006/03/vulnerability-in-gmail.html)

Hairbautt
03-04-2006, 04:40 PM
Well, I use gmail. I like it and I don't expect them to be perfect.

suprafreak6
03-04-2006, 05:12 PM
it still is in beta though so you gotta relize there are going to be holes..

Filliz
03-04-2006, 06:31 PM
it still is in beta though
At Google, what isn't?

S!X
03-04-2006, 07:10 PM
it still is in beta though
At Google, what isn't?

Good point :P

maebach
03-04-2006, 09:39 PM
14 year old kid :mellow:

meig
03-04-2006, 09:52 PM
Wow. Smart kid.

At that age, the only hacking I did was going onto my friends AIM accounts because they were stupid enough to give me their passwords :)

abu_has_the_power
03-04-2006, 10:29 PM
lol

they gotta pay this kid

ssj4conejo
03-11-2006, 08:29 AM
This kid is probably going to be a rich bastard in a few years.