Flaw turns Gmail into spamming machine

By Steven Musil, CNET News.com
Monday, May 12, 2008 08:28 AM

A "serious security flaw" in Gmail turns Google's e-mail service into a spamming machine, according to a recent security report.

INSERT, the Information Security Research Team, has created a proof of concept that exploits the "trust hierarchy" that exists between mail service providers. By exploiting a flaw in the way Google forwards messages, a spammer can send thousands of bulk e-mail messages through Google's SMTP service, bypassing Google's 500-address bulk e-mail limit and identity fraud protections.

The report noted that with the rising volume of spam, e-mail providers have turned to whitelists and blacklists to help root out IP addresses of known spammers. Because, Gmail falls into the trusted whitelist category, messages are allowed "carte blanche" to bypass spam filtering.

INSERT's report noted that no extraordinary Internet expertise is necessary to exploit the flaw:

In this regard, this document presents a vulnerability report and a proof of concept attack that demonstrate how anyone with no special internet access privileges other than being able to connect to SMTP (TCP port 25) and HTTP (TCP port 80) servers is able to exploit a single Gmail Account in order to be granted nearly unrestricted access to Google's massive white-listed SMTP relay infrastructure.

Google has offered no official comment on the report.

This article was originally a blog post on CNET News.com.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Replicating your infrastructure in a lab

Enterprise Servers & Storage

Learn two ways to replicate your current environment for testing and evaluation of new server platforms.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? HPC is not just reserved for the some obscure high-end scientific studies.

    David Scott from Intel Corporation gives you a quick tour to the process of developing HPC applications and the interesting world of HPC Applications in today's industries, including the lucrative oil industry.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajendhiran Sanggaran from Oracle explains the processes and important considerations required to enable IT to fuel your business to the next level of growth.
    Play video

Tags

  1. ad
  2. boost
  3. china
  4. cloud
  5. data
  6. deal
  7. developers
  8. ebay
  9. facebook
  10. fight
  11. firefox
  12. google
  13. icahn
  14. icann
  15. internet
  16. launch
  17. microsoft
  18. net
  19. online
  20. open
  21. privacy
  22. proxy
  23. report
  24. search
  25. site
  26. suit
  27. users
  28. web
  29. yahoo
  30. youtube

What's the Indian definition of privacy?

Blog thumbnail

Two days back, I was having dinner at an aunt's place. She is a leading doctor. We were discussing my school friend, who happens to be her patient.

My aunt..... by Swati Prasad

Read more »