Forums: Gmail Security Hole - Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

Gmail Security Hole

#16 User is offline   Sayian 

  • Private
  • Icon
  • Group: Members
  • Posts: 8
  • Joined: 02-October 04

Posted 03 December 2004 - 11:00 PM

course its google :D

Teh sexy google ;)
0

#17 User is offline   tshark 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 42
  • Joined: 15-September 04

Posted 04 December 2004 - 11:22 AM

Lone, the reason it doesnt matter if you change your pw or not is because they still have the session id that makes them auto login to your account. It says it in the article:

Quote

Once stolen, this cookie file allows the hacker to identify himself as the victim, without the need of a password. Even if the victim does change his password afterwards, it will be to no avail. "The system authenticates the hacker as the victim, using the stolen cookie file. Thus no password is involved in the authentication process. The victim can change his password as many times as he pleases, and it still won't stop the hacker from using his box", explains Goldshlagger.



- T
0

#18 User is offline   neon 

  • Private
  • Icon
  • Group: Members
  • Posts: 3
  • Joined: 15-February 04

Posted 21 December 2004 - 01:28 PM

Lone, on Nov 14 2004, 05:30 AM, said:

then why the hell i still getting the damn mailer daemons  <_<


actually tshark had a point but it's not what lone is referring to here.

Lone what you are getting is emails from a worm (trying to infect you). It's a fairly common one going around lately, not sure the name tho, i should look it up.

And yeah, werd@ building this up for the news.. Just another xss vuln.
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting