09 April 2008

Gmail Security Hole

This is what I heard from the Internet after browsing some webites.
For gmail users, please beware of this security hole. You should always log off Gmail after using it, because if you're not and you're unlucky, someone can steal information from your account.
This is how the scheme works. While you are logged in to gmail, try not to browse other website until you finish reading your email. Some website is prepared to alter your gmail filter when you visit this website. This condition only happen when your gmail account still opened on your browser.
By altering your gmail filter, attacker then can create an autoforward and delete for every email you receive. And this is very dangerous especially if you store a lot of confidential information in your mail account.
The last update is this hole has been fixed apparently, but altered filter can still be in place. So, if you are gmail user, please check your gmail filter before its too late. You can check it by clicking settings - filter at your gmail account. If you found some filter that you never create before, than it must be you have been attacked. The only thing you can do right now is to delete that filter immediately.
This hole is only applied to webmail and not to the email client program like Thunderbird or Outlook. Consider using this email client program to access your gmail account.

No comments: