Thursday, October 16, 2008   
  Search   
 
Register  Login  
Forums  
     Minimize  

Welcome to MeraWindows forums.

Thank you for being at the Microsoft Windows Community Site. You may have to register before posting in forums. It's absolutely free. After registering, you can get all the benefits available to our registered members, you can access our Downloads section, you can participate in contests, etc. You can post in forums in English as well as in Hindi, in fact we encourage you to use Hindi in your posts. If you have any problem with registration or login, please contact us.

     
  


 
  Microsoft Windows Forums  News & Feedback  Latest News  Flaw turns Gmail into spamming machine
Previous Previous
 
Next Next
New Post 5/13/2008 7:13 AM
User is offline vasu
1481 posts
MW Addict






Flaw turns Gmail into spamming machine 

Flaw turns Gmail into spamming machine

A "serious security flaw" in Gmail turns Google's e-mail service into a spamming machine, according to a recent security report.

 

INSERT, the Information Security Research Team, has created a proof of concept that exploits the "trust hierarchy" that exists between mail service providers. By exploiting a flaw in the way Google forwards messages, a spammer can send thousands of bulk e-mails through Google's SMTP service, bypassing Google's 500-address bulk e-mail limit and identity fraud protections.

The report notes that with the rising volume of spam, e-mail providers have turned to whitelists and blacklists to help root out IP addresses of known spammers. Because Gmail falls into the trusted-whitelist category, messages are allowed "carte blanche" to bypass spam filtering.

INSERT's report notes that no extraordinary Internet expertise is necessary to exploit the flaw:

In this regard, this document presents a vulnerability report and a proof-of-concept attack that demonstrate how anyone with no special Internet access privileges other than being able to connect to SMTP (TCP port 25) and HTTP (TCP port 80) servers is able to exploit a single Gmail account in order to be granted nearly unrestricted access to Google's massive whitelisted SMTP relay infrastructure.

Google has offered no official comment on the report.

This isn't the first Google tool to appeal to spammers. In April, my colleague Elinor Mills reported that spammers were now using Google Calendar.

Source : CNET


vasu follow me on

meraTechPort

Live Messenger Status, Click to talk !

 
New Post 5/13/2008 1:27 PM
User is offline Vishal Gupta
6202 posts
www.AskVG.com
Ultimate Member








Re: Flaw turns Gmail into spamming machine 

OMG.


Microsoft Windows MVP

Tweaking with Vishal

How to Use Smiley Code in Forum?
Promote MeraWindows at Your Blog / Site
Read Forum Guidelines
 
Previous Previous
 
Next Next
  Microsoft Windows Forums  News & Feedback  Latest News  Flaw turns Gmail into spamming machine


   Get Your Own E-Mail Account @MeraWindows.com Minimize  
New Page 1 New Page 1
Show your cool quotient with @merawindows.com email account