Gmail Bug Exposes E-mails to Hackers

By Ed Oswald | Published January 12, 2005, 3:23 PM

UPDATE Google has squashed a bug discovered by UNIX developers HBX Networks within Gmail that allows access to other users' personal e-mails. By altering the "From" address field of an e-mail sent to the service, hackers could potentially find out a user's personal information, including passwords.

Quick to respond, Google acknowledged the problem late Wednesday and has since corrected the problem for all users, a company source said.

At first glance, to the average user the e-mail would appear normal. But by clicking "show options" within the Gmail interface, the "Reply-To" field will show HTML code that is actually a formatted version of another user's e-mail, HBX wrote on its Web site.

HBX said that they think a missing character is tripping up Gmail and causing it to print whatever is in its cache, or memory, into the Reply-To field. The group did say much of what they saw was spam. However, what troubled them was in at least one case they were able to see a user's password.

"Regardless of the specific failure, the result is a compromise of the privacy of communications over Gmail," the organization said. "Usually, this only permits an attacker to examine recently-arrived spam in random user's inboxes - but message content does occasionally become more interesting."

The group urged Gmail users to contact Google and demand the problem be fixed, and warned about using the service for personal communications.

Comments

We fixed this some time ago. See our reply to the slashdot article here: http://it.slashdot.org/a...amp;tid=217&tid=218

Chris DiBona
Open Source Program Manage, Google Inc.

Score: 1

|

Chris way to go!
B.Preece
Suncoast Linux Users Group

Score: -1

|

Good to know--this could've (and may still) hurt google's rep alot even though betas are just that--beta. Now if Gmail was a full version, I must admit this would have been a pretty big deal. I don't use Gmail yet, not until it gets out of beta. Perhaps this was a good reason why, though I'm sure it was fixed by google inc. asap.

Score: 0

|

I Thought Gmail is still in beta. This is what Beta is for. I still say do not use it as personal mail. I use gmail for spam and subscribe to news letters. and sign up for stuff.

Score: 0

|

why the f*** don't they email google as opposed to releasing this information?

ffs ... you'd think the security group was headed up by yahoo and msn execs trying to knock google down a peg instead of helping the users.

Score: 0

|

Your right, its funny that they release it like it is some major thing, but in reality those of us who use gmail realize that it is still in beta testing, so it isn't like gmail is letting people use a buggy service, we have just chosen to test the service for bugs before the normal e-mail users get there hands on it.

If this security hole was found months from now when the service is made widely available to the public, then it would be a different story...

Score: 0

|

It's not all that surprising to find a 'security group' going against the SMTP standards when sending emails and then to advise the public that what they can do is bad and someone should stop them before informing a company with the power to put a stop to it.

So, Gmails validation of the SMTP syntax had an error. So what? It's still in Beta.

HBX Networks must be trying to render Gmail's feedback system useless as they're telling thousands, if not millions, of users to send this same message. Should a Gmail user even report a bug that they can't even replicate? Or should HBX Networks inform us as to exactly how they compromised our privacy so that we may have a valid reason to inform Gmail over and over and over....
This may seem "Ok" as it's telling Google to fix this particular problem but what about other bugs that may be discovered? Filtering through all this HBX endorsed spam may slow down the rate of development.

Gmail-Beta is all about developing an efficient emailing system so why would a "security group" want to tell millions of people to slow down it's development?

Score: 1

|

Secunia are also experts at releasing vulnerabilities to the public first...

Score: 0

|

...that's quite a glitch--

Score: 0

|

Passwords should never be sent by e-mail in the first place (and it annoys me that they so often are).

Here's the fact. Mail arrives and leaves gmail using a protocol called Simple Mail Transport Protocol, which was developed a very long time ago when the internet was a kinder, gentler place.

When you send an e-mail, first it goes to your ISP's mail server. The ISP's mail server spools it into a file, most commonly, and delivers it at some future point in time through a process called relaying.

The file is stored on disk in unencrypted form, most commonly under a common account. Anyone at the ISP can read the mail in the queue.

Once that is completed, the next thing that happens is that the file is sent, unencrypted, from a port on the mail server (whose address, under SPF, is conveniently recorded in the DNS record as being a mail server) to a known port on Google's e-mail server.

This exchange occurs using the same SMTP, an unencrypted protocol, travelling over on average at least 10 routers on internet, and whose path you have no control over. There is no end-to-end encryption, and so any of these routers that may have been compromised can see your message in plain text.

Google then stores this information in a database.

This attack was on the cache, and displayed the message, but only after a great many other people had been given the opportunity to review the data first.

You should never, ever send a password, credit card number or any other data you care about via e-mail. If you need something to be private, use PGP or GPG.

The thing about this bug is it displayed random data -- you couldn't control what random data. It might be passwords, or (most likely) it might be advertisements for Viagra and fake e-Mails from WAMU.

Any compromised router in the vicinity of google's system would be able to launch a directed attack against user's passwords and any other information sent in e-mail.

But users don't know any better

Score: 0

|

Nokia: Android? Are you crazy?

Rumors about new Android devices abound, but Nokia squashes this one.

What's Now: Drenched with 'Purple Ra1n,' iPhone users caught eating 'redsn0w'

Plus: Symantec and McAfee go to war, and what's LucasArts building in its top-secret, moon-shaped orbital facility?

Can Linux do BitLocker better than Windows 7?

Betanews kicks off a new series with a look at how the Linux operating system's FDE stacks up against BitLocker, the Windows feature that today commands a $120 premium.

Firefox 3.5: The need for speed

This has been the big payoff week for Mozilla's developers, who worked overtime to squeeze out the last drop of performance from their new JavaScript engine.

'GeoHot' gets a shower, cleans up nice, reveals new iPhone 3G S jailbreak

Either puberty has been very kind to the author of the new 'Purple Ra1n' jailbreak tool, or George Hotz may also have some adequate Photoshop skills.

Symantec goes live with Norton 2010 betas

Norton Internet Security and Norton Antivirus 2010 are now available for testing.

IE8 WSUS update push to begin August 25

After months of availability to users willing to seek it out, Internet Explorer 8 will be rolled into Windows Server...

In New York, online booze loses a Circuit Court decision

Court worried about gangster influence if liquor purchased directly.

Geeks vs. journalists: A tale of two worldviews

Recovery with Angela Gunn Why geeks think most mainstream journalism is flaky, and why the mainstream thinks geeks are trying to kill them. (They're both right.)

Fire in downtown Seattle data center knocks out businesses, online services

Small fire has global impact with payment centers, city services down.

What's Next: Obama gives 'Einstein' the go-ahead, while China gives 'Green Dam' a thumbs-down

Plus: If you put up a Web site and name it after you and you're a federal judge, you might not want a bunch of weird nudity hanging around on it.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

VirtualDub 1.9.3 Experimental

July 6 - 1:28 PM ET

CDBurnerXP Pro 4.2.4.1420

July 6 - 1:07 PM ET

AbiWord for Windows 2.7.6 Beta

July 6 - 12:46 PM ET

Notepad++ 5.4.4

July 6 - 12:25 PM ET

KeePass Password Safe (v2.x) 2.0.8

July 6 - 12:04 PM ET

ReactOS 0.3.10

July 6 - 11:43 AM ET

Tux Paint for Windows 0.9.21

July 6 - 11:22 AM ET