A proof of concept crafted by the
Information Security Research Team (INSERT) demonstrates how a security flaw in Google Gmail can turn the free email provider into a bulk spam distributor. The flaw remained exploitable as of Monday afternoon.
As of 3:00 PM (GMT -0400) today, the flaw we have reported remains unpatched and exploitable. We have ran a new experiment where we were able to use our attack to send 2,000 messages using one Gmail account. We would like to clarify to the security community that we have contacted Google about the issue more than a week ago and no response was provided despite our clear intent of cooperation regarding this matter.
Delicious |
Digg |
Reddit |
Technorati