Google fixes Gmail flaw discovered by teenager

Google rushed in to fix a minor glitch that was found in Gmail by a 14-year-old blogger calling himself Anthony. He was attempting to send an email JavaScript from his Yahoo account to his Gmail account when he stumbled onto this particular vulnerability.
Posted : Fri, 03 Mar 2006 13:56:03 GMT
Author : Abdul-Salaam Masheer
Category : Internet
News Alerts by Email ( click here )
Internet News | Home
Google rushed in to fix a minor glitch that was found in Gmail by a 14-year-old blogger calling himself Anthony. He was attempting to send an email JavaScript from his Yahoo account to his Gmail account when he stumbled onto this particular vulnerability.

In a blog, posted on http://ph3rny.blogspot.com/2006/03/vulnerability-in-gmail.html, Anthony says that he only tested it from Yahoo to Gmail, since sending the mail within Gmail filtered this problem, "Apparently JavaScript will run if it is within the preview of the message, " Anthony wrote.

"This is what the message has to compose of
· A short subject to increase the amount of code to run
· A short bit of text in the body so that the code isn't treated as quoted text
· And your code," he added.

Anthony felt that the flaw could be used to gather email addresses and thus compromise the account. But Google immediately fixed this flaw. "We learned of a minor security flaw in Gmail a little while ago and worked quickly to fix the problem, which has now been resolved," a representative for the Mountain View, California-based company said. He added that since it had been taken care of very rapidly, there was no question of exploiting it.

However, Google feels that users would be better off reporting to the company first rather than making such glitches public, "In the interest of minimizing the impact that security vulnerabilities have on our end users, we highly encourage anyone who discovers a vulnerability in a Google product or service to follow responsible disclosure policies by contacting us first at security@google.com," the company said in a statement.

Copyright, respective author or news agency

Share/Save/Bookmark

Article : Google fixes Gmail flaw discovered by teenager
Print this article
Email this article

Stay Updated
News gadget on your Google homepage
Subscribe to a news feed in Google Reader



Have your Say
Name
Email
Subject
Your Comment

Enter Verification code
 
  

 

 
Your Comments

wanted gmail.com
By: tonypanicker , Sun, 05 Mar 2006 17:41:51 GMT

how can i sign up gmail aaccount.


wanted
By: paing thu , Sun, 05 Mar 2006 07:59:21 GMT

i would like g mail account.for contect with some my friends.


mail sending ?querry.
By: Anup , Fri, 03 Mar 2006 19:02:42 GMT

how can i send application file .exe through the my mail acount?
Suggest a Alt way to send it.



More Internet News click here
Follow The Earth Times
Subscribe to RSS Follow Earth Times on TwitterNews by email
Share/Save/Bookmark

 
 



 
Subscribe to free Earthtimes
News Alerts by Email Click here
For RSS Feeds Click here
or Create your own RSS

Add to Google Toolbar
Breaking News
Press Releases
 
Vulnerability in Gmail blog


The Earth Times
News Category

© 2009 www.earthtimes.org, The Earth Times, All Rights Reserved | Privacy Policy
Earth Times accept no responsibility or liability either directly or indirectly for views or opinions expressed in articles or comments.