Gmail is not an iron wall

Gmail is not an iron wall
Gmail, a widely used email service under Google, has recently exposed a vulnerability that allows anyone to obtain a large number of Gmail email account information in order to post spam or even steal passwords. It is reported that the vulnerability may have existed for several years. The vulnerability was discovered by Oren Hafif, an employee from an Israeli security company who has previously discovered multiple Gmail vulnerabilities. Hafif said that by exploiting the vulnerability discovered this time, a large number of Gmail email accounts can be obtained within a few days or weeks. Although this vulnerability cannot directly steal account passwords or log in to accounts, it may put users at risk of spam, phishing or password theft. The reason why the vulnerability can be exploited is that Gmail has a little-known account sharing function, which allows users to "delegate" other users to log in to their own accounts. Last November, Hafif discovered that when trying to log in to someone else's account through the "delegate" function, you only need to make a slight change to the web page address that pops up to obtain the email address of another user. With the help of software that automatically changes web addresses, Hafif once collected 37,000 Gmail email addresses in two hours. In this regard, Hafif said that he had good reason to believe that all Gmail accounts may have been collected. In addition, he emphasized that the vulnerability affects not only personal mailboxes, but also corporate users who use Gmail mailboxes, and even Google itself. Hafif said that Google did not use cookies or other forms of authentication to display vulnerable pages, so it only needed to use anonymous software to obtain a large amount of user account information without being noticed. Hafif said that since Gmail has had a "delegation" function since 2010, the vulnerability may have existed for several years. As for how much account information has been secretly collected, it is unknown. A Google spokesperson said in an interview that the vulnerability has been successfully fixed.

As a winner of Toutiao's Qingyun Plan and Baijiahao's Bai+ Plan, the 2019 Baidu Digital Author of the Year, the Baijiahao's Most Popular Author in the Technology Field, the 2019 Sogou Technology and Culture Author, and the 2021 Baijiahao Quarterly Influential Creator, he has won many awards, including the 2013 Sohu Best Industry Media Person, the 2015 China New Media Entrepreneurship Competition Beijing Third Place, the 2015 Guangmang Experience Award, the 2015 China New Media Entrepreneurship Competition Finals Third Place, and the 2018 Baidu Dynamic Annual Powerful Celebrity.

<<:  China Mobile: TD-LTE voice call success rate has reached 98%

>>:  Nanjing Mobile 4G users were cheated and cried: the phone lost connection after turning on

Recommend

World Alzheimer's Day丨Keep the "eraser of memory" away from us

September 21, 2022 The 29th World Alzheimer's...

How do educational and training institutions attract new customers online?

On May 27, I was invited by a teacher from an edu...

Zhihu promotion and traffic generation skills!

There is a saying that is often circulated on the...

A complete list of short video operation content models

Recently, many friends have sent me private messa...

Flash is dying, Google acquires HTML5 development platform Divshot

H5 is gaining popularity, which always reminds pe...

SEM promotion: teach you how to do data analysis step by step!

Many people who have just started SEM find data a...

Nielsen: Social media helps TV shows

According to foreign media reports on August 5, t...

Community operation: How to operate a community from scratch?

1. Purpose Addressing current community needs: On...

Exploring the potential and challenges of developing games for Apple Watch

The developers of the first Apple Watch game are ...

Apple quickly withdraws iOS 14.3 after releasing it: Reason unknown

[[352022]] Apple did the same thing again. Wasn’t...