Gmail Hole Found and Fixed
Filed in: Google, Life Log, Security — November 1st, 2004SAN FRANCISCO – Google Inc. has fixed a security flaw in its Gmail Web-based e-mail service that allowed attackers to hijack users’ e-mail accounts.
“Google was recently alerted to a potential security vulnerability affecting the Gmail service. We have since fixed this vulnerability, and all current and future Gmail users are protected,” Google spokesman Nathan Tyler said.
…
The problem was in the way Gmail authenticated users. An attacker could steal a so-called cookie file identifying the user by making use of a seemingly innocent link to Google’s own Web site, according to a report on the Web site of the Israeli publication Nana NetLife Magazine on Thursday.
[ Read InfoWorld ]
Thought:
Google seems like busy fixing bugs since it released Google Desktop Search…
BTW, here is official Gmail bugs list. Gmail may not as good as you thought.


