Rating:
|
Digg this ::
Slashdot ::
Del.icio.us | [?]

As we all know, Gmail is the latest big e-mail service. The founder, Google, thought that only a web search engine it’s not enough, so they made a messenger and an e-mail server too. But they are still at the beginning, so they make mistakes. First, Google Talk, their messenger didn’t got very popular as they wanted. And now it seems that the e-mail server has problems of his own.
A teenager, named Anthony, found a flaw in the Gmail service, that allow Java scripts to run when you preview your message. This way, malicious code could be run which may even lead to compromise the Gmail account.
Anthony posted his findings on a website into which he demonstrated how he was able to run a script in the e-mail he sent from his Yahoo account to his Gmail account. Other people tried this and they succeeded. But Google found about the problem and shortly the flaw was repaired.
Google fixed the flaw “very shortly after the initial blog post went up,” a representative for the Mountain View, Calif., company said. “We learned of a minor security flaw in Gmail a little while ago and worked quickly to fix the problem, which has now been resolved,” the representative said.
Of course they got upset that Anthony didn’t reported his findings privately,but I guess it’s better that way, considering we all need to know if something is wrong and to see how they respond to the problem.
“We encourage all vulnerability reporters to follow responsible disclosure practices and notify vendors first before making the vulnerability public,” the representative said.
Flaws are very common in the online business, because you can cover all the problems. All that is important is to resolve them quickly. Like Google had done with the security hole they had that allowed all kind of phishing scams, spams and other kinds of attacks.
All went well, so you can stay relaxed. Google is watching.
Tags: Google, flaw, blogger, Java
No comments






