Gmail Accounts Vulnerable to XSS Exploit

alm4rr

Diamond Member
Dec 21, 2000
4,390
0
0
A security hole in GMail has been found (an XSS vulnerability) which allows access to user accounts without authentication. What makes the exploit worse is the fact that changing passwords doesn't help. The full details of the exploit haven't been disclosed. The vulnerability was reported by Israeli news site Nana. They were tipped off by an Israeli hacker. Google has been notified and they are working to close the hole. The Register has the story here.

http://www.theregister.co.uk/2004/10/29/gmail_vuln/
 

kamper

Diamond Member
Mar 18, 2003
5,513
0
0
It's still in beta. Anyone who's storing critical data in gmail deserves ... well they don't deserve it but they have only themselves to blame if something happens.

Still, not cool.
 

AFB

Lifer
Jan 10, 2004
10,718
3
0
Originally posted by: kamper
It's still in beta. Anyone who's storing critical data in gmail deserves ... well they don't deserve it but they have only themselves to blame if something happens.

Still, not cool.

As long as no one deletes my pr0n on there it's all good.