NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security

Security


Security Flaw Can Easily Turn Gmail into Your Worst Nightmare

Vulnerability can make Gmail a genuine spamming bot

By Bogdan Popa, Security and Search Engines Editor

12th of May 2008, 08:45 GMT

Adjust text size:


Gmail was released on April 1st, 2004
Enlarge picture
Gmail, Google's very popular email technology, which is for many users their main email service, can easily turn into your worst nightmare as a security glitch could allow
an attacker to use the service as the perfect spamming bot. According to security research team INSERT, the security glitch "is related to the risk of abusing the email forwarding option in Gmail accounts." In case an attacker manages to take advantage of the flaw, he could easily send a very large number of messages, obviously with spamming purposes.

It's interesting to note that the security researchers managed to send unsolicited messages to more than 4,000 email addresses in no less than 6 hours and "no measures took place that would have prevented us from keeping sending more messages." And obviously, more Gmail accounts exploited means more spam messages sent to inboxes from all over the world. "By deploying this attack with 100 Gmail accounts simultaneously, the message rate would exceed 1,000 messages per minute," the researchers explain.

Gmail is usually a safe and trusted email service and email technologies from all over the world included it on the whitelist, allowing messages sent by Gmail accounts to reach their inboxes. Imagine that such a security glitch could prove to be extremely dangerous for them, unless Gmail is blacklisted.

"It is possible to assemble an attack that would have results similar to those of a botnet based spam by compromising a relatively small number of Gmail accounts, but without the need for thousands of zombie computers. Nevertheless, an attacker could also reach levels similar to those of a small botnet by exploiting only one Gmail account given enough time," the INSERT researchers explain.

At this time, we're still waiting for an official comment from Google's representatives but, in case you want to get more info on this topic, read the INSERT advisory available here.

TAGS:

gmail | security | spam | email | google
Read by 1,035 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.7/5) 4 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


YouTube Glitch Lets Users Access Others' Gmails

Gmail, Yahoo Messenger, Bank Account - All Sharing the Same Password

Gmail and Yahoo Mail - Spammers' Favorite Services

Gmail Introduces New Function to Send Emails to the Past

Gmail to Provide Language Translation

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM