Jump to content
xisto Community
Sign in to follow this  
kudmus

Google Can Send Spam Gmail can be used as a Spam Bazooka

Recommended Posts

For those who are so loyal to Page and Brin that they can't let go of their Gmail accounts. I've got some news for you.

INSERT, the Information Security Research Team, has sucessfully created a proof of concept exploiting the “trust hierarchy” that exists between mail service providers. Taking advantage of the way Gmail forwards messages, the team was able to send 4000 messages in a short period of time from a single account without any countermeasures taken by Google.
Using Google as an open email relay is highly desierable for spammers because Gmail is trusted by most email providers — making messages sent though Gmail immune to most spam filtering.

Since the messages are delivered by Google’s own servers, an attack based on this flaw is able to bypass all spam filters that are based on the blacklist / whitelist concept. We were able to confirm that this vulnerability is indeed exploitable by crafting a proof of concept attack that allowed us to send forged email messages unrestrictedly through Google’s server infrastructure.

There has been no official comment by Google on this matter yet, but I’m hoping the problem will be resolved in short order. The vulnerability isn’t as serious as past ones that exposed contact lists, or let attackers steal cookies, but that shouldn’t stop it from being high priority.


I got this info from Garet Rogers' blog titled Gmail can be used as a spam bazooka

Notice from rvalkass:

You must put Quote tags around any content not original to the forums.

Share this post


Link to post
Share on other sites

I don't know what much can be done without limiting legitimate users of gmail. I suppose there can be a limit to how much gmail will actually forward but if they set that limit too low, then legitimate users who may just need this feature would be affected. Too high and it won't do too much good. Many people would have already received the spam.

Hey Thanx for that advice. Is it just good practice or it's one of the rules of these forums.Could that be the reason why one of my posts titled "Carefour sensorship- Google or China" was deleted?
Could it be because someone is going around the net getting rid of such info?


If you understand anything about how the internet works you'd know that it is impossible for anybody to be "internet police" and "go around the net and deleting stuff". The only real action that could be taken against your website is finding and exploiting vulnerabilities in your server or code, or i suppose if your server was located in a country with no so free speech they could have a warrant to actually take your server away but this doesn't apply to Xisto. Your topic was most likely deleted because it was breaking one of the forum rules.

Share this post


Link to post
Share on other sites

hey i dont think so because google is a great company and also its a big company and reputed one but its not impossible for google to send spams but its rare.Any way you can try google it anywayThank you very much

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  

×
×
  • Create New...

Important Information

Terms of Use | Privacy Policy | Guidelines | We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.