Read Latest Entries..: (Post #33) by Laurence on Aug 29 2007, 08:41 PM. (Line Breaks Removed)
It's very surprising it was found by a teenager. Us teenagers have nothing better to do. I'm only 14 and I know how to do a lot of things on the computer than other people don't. Lol my parents have a hard time checking their email. ... read more.
Anthony show in a blog his gmail discovered exploit. He said that he tried to send an Javascript messages to his own gmail mailbox and he discovered that that small code was really executed. This kind of failures allows any person to steal data, mail address, informations etc. Althougt gmail already correct this exploit.
Who's really and truly surprised that a teenager found this?
I'm not. Teens are always into something. Fortunately, a lot of them - the ones we don't hear about in the news or talk about - are into something that's actually productive ... or at least not destructive. Like this kid's interesting discovery.
As for Google: I don't suppose we should expect perfection from them, but it would be nice to know that the e-mail accounts are at least reasonably secure.
Who's really and truly surprised that a teenager found this?
I'm not. Teens are always into something. Fortunately, a lot of them - the ones we don't hear about in the news or talk about - are into something that's actually productive ... or at least not destructive. Like this kid's interesting discovery. As for Google: I don't suppose we should expect perfection from them, but it would be nice to know that the e-mail accounts are at least reasonably secure.
Just the other day, my friend must have found this because he also sent me some test emails like that. But the surprising thing was, he tried it again a few minutes later and it didn't work!
Just the other day, my friend must have found this because he also sent me some test emails like that. But the surprising thing was, he tried it again a few minutes later and it didn't work!
Shows you how fast Google is at fixing things!
[N]F
well i dont understand why people are so obsessed with Google and try to be protective for it... Google had a flaw in something as basic as a web-based email, that is bad. Instead of accepting it people give excuses or try to defend google. If that same thing Microsoft had done, i am sure tens of others would have written dozens of posts condemning the company.
If there is a company or organisation that i can forgive for making mistakes is the Open Source, since they are already social workers in the first place! Whereas neither Microsoft nor Google work for free. Both suck money.
If there is a company or organisation that i can forgive for making mistakes is the Open Source, since they are already social workers in the first place! Whereas neither Microsoft nor Google work for free. Both suck money.
I think that most of us cut Google a lot of slack because we, the users, don't pay them for the things that we use (e-mail, Web space, et cetera). Typically, at least for me, I can just say, "Well, it's free, so I can't complain" when something goes wrong.
Besides: Google fixed the coding problem very quickly, which leads me to believe that they're not trying to screw us over even if we *aren't* paying customers.
Just the other day, my friend must have found this because he also sent me some test emails like that. But the surprising thing was, he tried it again a few minutes later and it didn't work!
Shows you how fast Google is at fixing things! tongue.gif
[N]F
True nightfox, but these things shouldn't be happening at all. Google is a very experienced and dependable Search Engine for people all over the world. If things like this start to happen with their e-mailing system then people will not trust Google anymore ... even with their popular Search Engine. But I agree, it is good to see that Google at least knows what's happening and you know how it is nowadays ... people are always protective of their information.
QUOTE
Who's really and truly surprised that a teenager found this?
I'm not. Teens are always into something. Fortunately, a lot of them - the ones we don't hear about in the news or talk about - are into something that's actually productive ... or at least not destructive. Like this kid's interesting discovery.
True. These are the "Kids of the future", they are always on the look out for suspicious things and will do anything to alert the authorities. In this case, the teenager was smart to post this news publically. At least someone from Google managed to pick this news up!
actually, gmail does have a lot of flaws, mainly security issues. I'm not sure if this information is completely accurate because i got it from a third party scource or wutever its called but here it is.
QUOTE
Google offers more storage for your email than other Internet service providers that we know about. The powerful searching encourages account holders to never delete anything. It's easier to just leave it in the inbox and let the powerful searching keep track of it. Google admits that deleted messages will remain on their system, and may be accessible internally at Google, for an indefinite period of time.
A new California law, the Online Privacy Protection Act, went into effect on July 1, 2004. Google changed their main privacy policy that same day because the previous version sidestepped important issues and might have been illegal. For the first time in Google's history, the language in their new policy made it clear that they will be pooling all the information they collect on you from all of their various services. Moreover, they may keep this information indefinitely, and give this information to whomever they wish. All that's required is for Google to "have a good faith belief that access, preservation or disclosure of such information is reasonably necessary to protect the rights, property or safety of Google, its users or the public." Google, you may recall, already believes that as a corporation they are utterly incapable of bad faith. Their corporate motto is "Don't be evil," and they even made sure that the Securities and Exchange Commission got this message in Google's IPO filing.
Google's policies are essentially no different than the policies of Microsoft, Yahoo, Alexa and Amazon. However, these others have been spelling out their nasty policies in detail for years now. By way of contrast, we've had email from indignant Google fans who defended Google by using the old privacy language — but while doing so they arrived at exactly the wrong interpretation of Google's actual position! Now those emails will stop, because Google's position is clear at last. It's amazing how a vague privacy policy, a minimalist browser interface, and an unconventional corporate culture have convinced so many that Google is different on issues that matter.
After 180 days in the U.S., email messages lose their status as a protected communication under the Electronic Communications Privacy Act, and become just another database record. This means that a subpoena instead of a warrant is all that's needed to force Google to produce a copy. Other countries may even lack this basic protection, and Google's databases are distributed all over the world. Since the Patriot Act was passed, it's unclear whether this ECPA protection is worth much anymore in the U.S., or whether it even applies to email that originates from non-citizens in other countries.
Google's relationships with government officials in all of the dozens of countries where they operate are a mystery, because Google never makes any statements about this. But here's a clue: Google uses the term "governmental request" three times on their terms-of-use page and once on their privacy page. Google's language means that all Gmail account holders have consented to allow Google to show any and all email in their Gmail accounts to any official from any government whatsoever, even when the request is informal or extralegal, at Google's sole discretion. Why should we send email to Gmail accounts under such draconian conditions?
Problem 2: Google's policies do not apply
The phrasing and qualifiers in the Gmail privacy policy are creepy enough, but nothing in any of Google's policies or public statements applies to those of us who don't have Gmail accounts. Google has not even formally stated in their privacy policy that they will not keep a list of keywords scanned from incoming email, and associate these with the incoming email address in their database. They've said that their advertisers won't get personally identifiable information from email, but that doesn't mean that Google won't keep this information for possible future use. Google has never been known to delete any of the data they've collected, since day one. For example, their cookie with the unique ID in it, which expires in 2038, has been tracking all of the search terms you've ever used while searching their main index.
Matt Cutts, a software engineer at Google since January 2000, used to work for the National Security Agency.
Keyhole, the satellite imaging company that Google acquired in October 2004, was funded by the CIA.
"We are moving to a Google that knows more about you." — Google CEO Eric Schmidt, February 9, 2005
Problem 3: A massive potential for abuse
If Google builds a database of keywords associated with email addresses, the potential for abuse is staggering. Google could grow a database that spits out the email addresses of those who used those keywords. How about words such as "box cutters" in the same email as "airline schedules"? Can you think of anyone who might be interested in obtaining a list of email addresses for that particular combination? Or how about "mp3" with "download"? Since the RIAA has sent subpoenas to Internet service providers and universities in an effort to identify copyright abusers, why should we expect Gmail to be off-limits?
Intelligence agencies would love to play with this information. Diagrams that show social networks of people who are inclined toward certain thoughts could be generated. This is one form of "data mining," which is very lucrative now for high-tech firms, such as Google, that contract with federal agencies. Email addresses tied to keywords would be perfect for this. The fact that Google offers so much storage turns Gmail into something that is uniquely dangerous and creepy.
Problem 4: Inappropriate ad matching
We don't use Gmail, but it is safe to assume that the ad matching is no better in Gmail, than it is in news articles that use contextual ad feeds from Google. Here's a screen shot that shows an inappropriate placement of Google ads in a news article. We also read about a lawyer who is experimenting with Gmail. He sent himself a message, and discovered that the law practice footer he uses at the bottom of all of his email triggered an ad for a competing law firm.
Another example is seen in the Google ads at the bottom of this story about Brandon Mayfield. There are two ads. One mentions sexual assault charges (sex has nothing to do with the story), and the other is about anti-terrorism. The entire point of this article, as well as a New York Times piece on May 8, 2004, is that a lawyer has had his career ruined due to overreaction by the FBI, based on disputed evidence. He was arrested as a material witness and his home and office were searched. The NYT (page A12) says that "Mr. Mayfield was arrested before investigators had fully examined his phone records, before they knew if he had ever met with any of the bombing suspects, before they knew if he had ever traveled to Spain or elsewhere overseas. His relatives said he had not been out of the United States for 10 years." The only evidence is a single fingerprint on a plastic bag, and some FBI officials have raised questions about whether this print is a match. While Mr. Mayfield will get his day in court, it appears that Google's ads have already convicted him, and for good measure added some bogus sexual assault charges as well. Would Mr. Mayfield be well-advised to send email to Gmail account holders to plead his case?
The Wichita Eagle is pleased to present Google's recommendation for an alarm company that can "protect your home and family." One tiny problem is that the trigger for this ad is an article about an alarm installer who worked for this company for 14 years, while moonlighting as a serial killer.
Our last example shows three ads fed by Google at the bottom of a Washington Post column titled "Gmail leads way in making ads relevant." The columnist argues that Google's relevant ads improve the web, and therefore she finds nothing objectionable about Gmail. These Google-approved ads offer PageRank for sale, something which only a year ago, Google would have considered high treason. Yes, these ads are "relevant" — the column is about Google, and the ads are about PageRank. But here's the point: A relevant ad that shows poor judgment is much worse than an irrelevant ad that shows poor judgment. The ads at the bottom of her column disprove her pro-Google arguments. She has no control over this, and is probably not even aware that it happened.
Most writers, even if they are only writing an email message instead of a column in a major newspaper, have more respect for their words than Google does. Don't expect these writers to answer their Gmail.
Esther Dyson, queen of the digerati, gets it wrong
"We're not going to have any choice but to send mail to people at Gmail just to function in the e-mail world," says Daniel Brandt, founder of the Google-Watch.org Web site. "And what guarantees do we have that all this won't end up on some bureaucrat's desk at some intelligence agency someday?" But those who support Gmail say such privacy concerns are not Google issues so much as constitutional ones, best addressed to Congress and law-enforcement agencies. "They've got a beef with the wrong person. The problem there is the FBI, not Google," says Dyson. "And in the scheme of things, I'd rather have Google than my employer have access to my personal mail." — Baltimore Sun, 20 May 2004
The point is this: Some two-thirds of all Google searches come in from outside the U.S., and Gmail will also have a global reach. We're not dealing with only the FBI (and yes, the same privacy advocates who oppose Gmail are dealing with the FBI), but potentially with hundreds of agencies in dozens of countries. Google has no data retention policies, and never comments on their relationships with governments. The problem must be addressed at the source, which is Google. Elitist digerati do a disservice to the entire world when they assume such narrow points of view.
Privacy: Not enough, and too much!
While there's no privacy for non-Gmail users who receive mail from a Gmail account and might want to reply, there is too much privacy for those who use Gmail to send spammy, abusive, or threatening messages. Unlike Hotmail, Yahoo mail, and most other web mail services, browser-based Gmail does not show the originating IP address in the header. This means that system administrators who are trying to stop abuse cannot identify a Gmail abuser without asking Google for assistance. And normal users, assuming they can read headers, cannot check the identity of someone sending from Gmail. (With an IP address, you can at least do a quick check on the country or city of origin by looking it up at dnsstuff.com or some similiar service.) Since Google always seems to be too busy making billions to bother with complaints, many decide it's easier to just say "no" to all Gmail.
So yeah, it doesn't suprise me at all tht a 14 year old kid could find tht flaw. Gmail is very good but they still have issues to work out. They need to change the privacy policy big time and up security. So if u have gmail, i suggest not storing any important documents on it.
Notice from moonwitch:
Please use quote tags, it cost you 38 credits - automated credit deduction script.
It's very surprising it was found by a teenager. Us teenagers have nothing better to do. I'm only 14 and I know how to do a lot of things on the computer than other people don't. Lol my parents have a hard time checking their email.
Wow I Never Knew Google Would Be So Dumb! A Little Java Script Causes A Vulnerability! Even At His Age, I Can't Believe It! I Guess I know Why It's Still In BETA Release lol Usually When Someone Discovers This Kind Of Glitch, The Company Which Is Gmail In This Case Tracks The Person Who Discovered This, And Try To Patch The Glitch Together. I Heard You Get Some Reward. I Wonder What It Is.
It's going to happen. Code isn't perfect and sometimes people will find ways around that you (and the rest of the team) didn't even think or know about. It's so long as they do something about it quickly is what counts.
It's just like the other day I had a client who wanted to know how to lock down a G4 tower he was giving his 15 year old technical savvy kid. He wanted a "foolproof" way and I was honest with him, there is no fool proof way. Chances are the kid is the one with too much time to go poking through and learn Unix. I told him what software to purchase to filter out sites, set-times, etc. And then I went on after installing that used a few more tricks to block specific sites and ip's at the server level (okay computer level) from the Unix Admin playbook. Same tricks we used back in the day with other Unix distros.
Still I'm sure given enough time the kid could figure out a way around all of it. Especially since the parent is primarily into Macs because he runs a photography studio.
I agree completely with pretty much all of that. There just isn't a way of blocking out absolutely everything. If there was, we wouldn't have these problems. As soon as someone develops some clever way of keeping out hackers etc., someone else comes up with an even more clever way of getting past the last security breakthrough. It's not a case of developing a foolproof piece of software/hardware, it's about staying one step ahead of the people who make the security needed.
It's going to happen. Code isn't perfect and sometimes people will find ways around that you (and the rest of the team) didn't even think or know about. It's so long as they do something about it quickly is what counts.
It's just like the other day I had a client who wanted to know how to lock down a G4 tower he was giving his 15 year old technical savvy kid. He wanted a "foolproof" way and I was honest with him, there is no fool proof way. Chances are the kid is the one with too much time to go poking through and learn Unix. I told him what software to purchase to filter out sites, set-times, etc. And then I went on after installing that used a few more tricks to block specific sites and ip's at the server level (okay computer level) from the Unix Admin playbook. Same tricks we used back in the day with other Unix distros.
Still I'm sure given enough time the kid could figure out a way around all of it. Especially since the parent is primarily into Macs because he runs a photography studio.
Anyway, I've always found it highly entertaining that most of the reported or publicised successful hacking attempts are by teenagers. Personally, I'm at a loss as to why people are so amazed by this sort of thing, as today's teenagers have grown up with all of this technology. Sure, they haven't got all of the experience behind them as older "hackers" do, but they have the same capability. Sometimes it's the younger generation that spot a simple flaw in security whereas those who know more ways to get in to a secure site probably overlook the simple methods for that reason alone. If a site/company is supposedly hard to hack in to, why bother with the simple methods? Surely they wouldn't work?
Regardless of that, teenage computer whizzes are forever popping up in the news. Google's not necessarily more secure than any other major site, and it always amuses me when people believe otherwise.
Hello everyone. I have a dell desktop running windows xp home edition. AVG virus checker found an
exploit in Firefox's application database in My Documents. I moved it to the "vault" in AVG.
I have several clients to check the safety of my computer and it seems like my machine is secure,
however, there is one problem. My DHCP-cable modem is directly hooked to my computer. However,
even when the computer is idle, the "Send/recieve" LED's (lights) constantly blink. Do I still
have the exploit or somehow I can't catch the "Trojan" the exploit installe....
WARNING: To all members While browsing the forums, you might face a strange pop-up asking
you to download a .wmv file. DO NOT download and/or try to play this. The pop-up looks somewhat like
this (provided by Dha: I believe this is being spread through one of the Ads displayed at Asta.
Some guy has this worm embedded in his ads - that's the only logical explanation I can find..
Different anti-virus might identify it with different names - but essentially, it's a variant of
the following worm. Most likely it's coming from an ad of taalkzforum.....
So far there isn't a patch and the tests have been conducted on a fully uptodate Windows XP
Machine running IE6 and confirmation on IE7 Beta 2 also suffering. Here's the link, test your
browser and see if you're vulnerable. http://secunia.com/advisories/19521/ Be sure that you
get notified of the update for this or just continue keep checking for Windows updates. I don't
run IE6, so cannot confirm it but others have said it does exploit them. Cheers, MC....
A critical vulnerability was found in some versions of Apple Computer's popular iTunes. This
vulnerability could enable attackers to remotely take over a user's computer This vulnerability
existed on the earlier version of iTunes 6. However, Itwas not fixd by the newest security update.
iTunes 6 Windows version are affected. They are still trying to determine whether Mac OS X version
affected. http://news.com.com/Apple+iTunes+security+...ml?tag=nefd.top ....
Acyd Burn the Development Team Leader of phpBB posted this today, looks like another phpBB
exploit... /sad.gif' border='0' style='vertical-align:middle' alt='sad.gif' /> here's the
upgrade link, upgrade now... http://www.phpbb.com/downloads.php QUOTE Hi everyone, phpBB
Group announces the release of phpBB 2.0.17, the "no, we did not forget naming it last time"
release. This release addresses several bugfixes and some low security issues as well as the
recently seemingly wide-spread XSS issue (only affecting Internet Explorer). Please have a look
down this....
From SecurityFocus http://www.securityfocus.net/archive/1/395...10/2005-04-16/0 There is a _New_
exploit which affects the MSHTA (Microsoft HTML Application Host), using a simple program it's
possible to create file from a *.hta with a _strange_ extenstion(*.foo *.ghgh *.asd) and this file
will be executed by the MSHTA so if u put some malicious Vbs or JS in the *.hta the risk is very
high.... http://www.frsirt.com/exploits/20050414.ms05016.php this is the source of the program
to create the malicious files I've tested it on Xp Sp1 and Xp SP2 and both sy....
The past day 12, Microsoft published another new bulletin of security: MS05-020 . This time is a
remote code execution. The immediate update is advised, due to being a critical bug. First exploit
already has published it SkyLined /mad.gif' border='0' style='vertical-align:middle'
alt='mad.gif' /> ....
Looking for gmail, exploit, discovered, 14, years, boy
Searching Video's for gmail, exploit, discovered, 14, years, boy
Express your Opinions, Thoughts or Contribute more info. to help others.
Ask your Doubts & Queries to get answers, So that "Together We can help others!"
Register FREE for AD-FREE
forum, Create your own topics, Ask Questions, track topics, setup
subscriptions & notifications and Get a Free Website w/ Email and FTP.