<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A flaw in Google&#8217;s G-Mail system allowed anyone access to any mailbox</title>
	<atom:link href="http://www.exploitx.com/151/a-flaw-in-googles-g-mail-system-allowed-anyone-access-to-any-mailbox/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.exploitx.com/151/a-flaw-in-googles-g-mail-system-allowed-anyone-access-to-any-mailbox/</link>
	<description>Technology &#38; Security Tips &#38; Guides</description>
	<lastBuildDate>Mon, 17 Apr 2006 18:56:17 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Peter Holloway</title>
		<link>http://www.exploitx.com/151/a-flaw-in-googles-g-mail-system-allowed-anyone-access-to-any-mailbox/comment-page-1/#comment-98</link>
		<dc:creator>Peter Holloway</dc:creator>
		<pubDate>Tue, 21 Feb 2006 22:33:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.exploitx.com/151/a-flaw-in-googles-g-mail-system-allowed-anyone-access-to-any-mailbox/#comment-98</guid>
		<description>I submitted (the above) Dec 3, 2005 comment. Is there any way to get a technical response to this inquiry? 

Thank you.</description>
		<content:encoded><![CDATA[<p>I submitted (the above) Dec 3, 2005 comment. Is there any way to get a technical response to this inquiry? </p>
<p>Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Holloway</title>
		<link>http://www.exploitx.com/151/a-flaw-in-googles-g-mail-system-allowed-anyone-access-to-any-mailbox/comment-page-1/#comment-55</link>
		<dc:creator>Peter Holloway</dc:creator>
		<pubDate>Sat, 24 Dec 2005 06:36:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.exploitx.com/151/a-flaw-in-googles-g-mail-system-allowed-anyone-access-to-any-mailbox/#comment-55</guid>
		<description>I discovered I am a &quot;targeted victim&quot;. I noticed something funny about my Gmail Login window, which blinked once and auto-filled the login name with another person&#039;s name -- a name I recognize as an employee in the company I work for.

When I checked the FORMS tab under Page Info, I found a form that posted a Form Action &quot;https://www.google.com/accounts/ServiceLoginAuth&quot;.  In this form, there is a hidden continue to &quot;http://www.google.com/gmail?&quot;, a hidden mail service, a text Email containing the HR persons first and last names, a Passwd field containing &quot;********&quot; (not the real password), a PersistanCookie checkbox marked &quot;yes&quot; and, finally, a null field that submits on &quot;Sign in&quot;.

It seems that this employee has exploited the Gmail login vulnerability described above and is likely eavesdropping in on my personal Gmails. 

Isn&#039;t this illegal? Seems like interstate wiretapping to me, or a least a violation of the Communications Act of 1986.

Is there any way that the &quot;********&quot; Passwd is detectable? How did this form get into an Info Page on my browser? I understand that the original bug reported above allowed someone to access anyone else&#039;s Gmail account before it was corrected. Can this person still be hacking me even now? If so, do you think this person has criminal or civil exposure? Does it help to contact &quot;authorities&quot; or even a lawyer?

I want to nail this person!

Can you help me? I would really appreciate it.</description>
		<content:encoded><![CDATA[<p>I discovered I am a &#8220;targeted victim&#8221;. I noticed something funny about my Gmail Login window, which blinked once and auto-filled the login name with another person&#8217;s name &#8212; a name I recognize as an employee in the company I work for.</p>
<p>When I checked the FORMS tab under Page Info, I found a form that posted a Form Action &#8220;https://www.google.com/accounts/ServiceLoginAuth&#8221;.  In this form, there is a hidden continue to &#8220;http://www.google.com/gmail?&#8221;, a hidden mail service, a text Email containing the HR persons first and last names, a Passwd field containing &#8220;********&#8221; (not the real password), a PersistanCookie checkbox marked &#8220;yes&#8221; and, finally, a null field that submits on &#8220;Sign in&#8221;.</p>
<p>It seems that this employee has exploited the Gmail login vulnerability described above and is likely eavesdropping in on my personal Gmails. </p>
<p>Isn&#8217;t this illegal? Seems like interstate wiretapping to me, or a least a violation of the Communications Act of 1986.</p>
<p>Is there any way that the &#8220;********&#8221; Passwd is detectable? How did this form get into an Info Page on my browser? I understand that the original bug reported above allowed someone to access anyone else&#8217;s Gmail account before it was corrected. Can this person still be hacking me even now? If so, do you think this person has criminal or civil exposure? Does it help to contact &#8220;authorities&#8221; or even a lawyer?</p>
<p>I want to nail this person!</p>
<p>Can you help me? I would really appreciate it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

