Gmail is not an iron wall

Gmail is not an iron wall
Gmail, a widely used email service under Google, has recently exposed a vulnerability that allows anyone to obtain a large number of Gmail email account information in order to post spam or even steal passwords. It is reported that the vulnerability may have existed for several years. The vulnerability was discovered by Oren Hafif, an employee from an Israeli security company who has previously discovered multiple Gmail vulnerabilities. Hafif said that by exploiting the vulnerability discovered this time, a large number of Gmail email accounts can be obtained within a few days or weeks. Although this vulnerability cannot directly steal account passwords or log in to accounts, it may put users at risk of spam, phishing or password theft. The reason why the vulnerability can be exploited is that Gmail has a little-known account sharing function, which allows users to "delegate" other users to log in to their own accounts. Last November, Hafif discovered that when trying to log in to someone else's account through the "delegate" function, you only need to make a slight change to the web page address that pops up to obtain the email address of another user. With the help of software that automatically changes web addresses, Hafif once collected 37,000 Gmail email addresses in two hours. In this regard, Hafif said that he had good reason to believe that all Gmail accounts may have been collected. In addition, he emphasized that the vulnerability affects not only personal mailboxes, but also corporate users who use Gmail mailboxes, and even Google itself. Hafif said that Google did not use cookies or other forms of authentication to display vulnerable pages, so it only needed to use anonymous software to obtain a large amount of user account information without being noticed. Hafif said that since Gmail has had a "delegation" function since 2010, the vulnerability may have existed for several years. As for how much account information has been secretly collected, it is unknown. A Google spokesperson said in an interview that the vulnerability has been successfully fixed.

As a winner of Toutiao's Qingyun Plan and Baijiahao's Bai+ Plan, the 2019 Baidu Digital Author of the Year, the Baijiahao's Most Popular Author in the Technology Field, the 2019 Sogou Technology and Culture Author, and the 2021 Baijiahao Quarterly Influential Creator, he has won many awards, including the 2013 Sohu Best Industry Media Person, the 2015 China New Media Entrepreneurship Competition Beijing Third Place, the 2015 Guangmang Experience Award, the 2015 China New Media Entrepreneurship Competition Finals Third Place, and the 2018 Baidu Dynamic Annual Powerful Celebrity.

<<:  China Mobile: TD-LTE voice call success rate has reached 98%

>>:  Nanjing Mobile 4G users were cheated and cried: the phone lost connection after turning on

Recommend

Are the popular smart TVs facing alienation from the younger generation?

In the middle of the year, promotional activities...

How do small and medium-sized enterprises choose server leasing?

How do small and medium-sized enterprises choose ...

Stegosaurus: A hug of love and fear of being hurt

Stegosaurus is one of the most well-known dinosau...

How effective is 58.com’s promotion? Doing this will get you more resources!

As the Internet has developed to this day. Many t...

How to build a growth system based on user behavior?

This article is based on the "WHAT-HOW-WHY&q...

ROG's ultimate belief! How powerful is the overclocking brother from ASUS?

The ultimate flagship returns ASUS Republic of Ga...

QQ Groups to be closed? Tencent is furious

Dear users, due to business adjustments, our comp...

Double "new evidence" support! Good news for melanoma patients!

At the just-concluded 2024 European Society for M...

29 suggestions for brand placement on Xiaohongshu!

Xiaohongshu’s strategy has changed. Last year, it...

Lao Duan said: The future of cable network is integrated TV

After the launch of iQiyi Ultra HD Box and TCL iQ...