• On CHOW: Does drinking ice water burn calories?

March 2, 2006 4:30 PM PST

Google fixes 'minor' Gmail flaw

Google has fixed a flaw in its Gmail Web based e-mail service after the problem was disclosed by a blogger, the company said Thursday.

The flaw could allow JavaScript code to run when viewing a message in Gmail, potentially allowing malicious code to be used by an attacker to compromise a Gmail account, according to a blogger who calls himself "Anthony."

The blogger, who claims to be a 14-year-old student, found the flaw when sending code from his Yahoo Web mail account to his Gmail account, he wrote on Wednesday. The Web log is hosted by Google's Blogger service.

Google fixed the flaw "very shortly after the initial blog post went up," a representative for the Mountain View, Calif., company said. "We learned of a minor security flaw in Gmail a little while ago and worked quickly to fix the problem, which has now been resolved," the representative said.

Because the vulnerability was fixed quickly, it likely never was exploited in any attacks, the representative said. Still, Google would have preferred to have been alerted to the flaw privately, instead of via a public blog.

"We encourage all vulnerability reporters to follow responsible disclosure practices and notify vendors first before making the vulnerability public," the representative said.

Flaws in online services are found regularly. Last December, Google fixed a security hole in the mechanism it uses to generate error pages for forbidden redirects and pages that don't exist on the Google Web site. The flaw opened the door to phishing scams, account hijacks and other attacks.

Similar flaws have been discovered and fixed in other parts of Google's Web site, as well as in Microsoft's Xbox 360 Web site and Yahoo's Web-based e-mail service.

See more CNET content tagged:
Gmail, flaw, blogger, Google Inc., Yahoo! Inc.

Add a Comment (Log in or register) 7 comments
14?
by oo7evan March 2, 2006 4:59 PM PST
Why is a 14 year old sending java script around?
Reply to this comment View all 2 replies
Google mailing list service 'groups'
by n3td3v March 3, 2006 4:37 AM PST
I disclosed insecure script handling on Google's service.

The flaw was able to harvest millions of e-mail addresses.

The flaw was able to hi-jack entire groups

Compromise owner and moderator e-mail accounts

Leave a mailicious owner and moderator account in thousands of groups

Was disclosed to the major mailing lists in December 2005 as "Google is vulnerable from XSS attack"

50 to 80 days later, still was no fix.

Put the flaw on Digg.com as "Unpatched: Google attack vector" and the flaw was finally fixed, weeks after that.

Major delay for a flaw which is able to cause global consequence to spam and phishing in months and years to come.

Maybe the entire list of e-mail addresses should be put up on eBay?

Your corporate and consumer e-mail spam and phishing coming at you due to a javascript flaw thats "minor".

I wonder how much money will be made from the sale? eBay will be forced to pull the sale, but at least the timely sale will get media attention.

Regards,

n3td3v

The harvest is still continuing to this day because of the malicious owner and moderator accounts left on thousands of existing groups, which pick-up new members as they join a group.

Google Groups owned? You decide.
Reply to this comment View reply
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right