On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

May 9th, 2008

Gmail can be used as "Spam Bazooka"

Posted by Garett Rogers @ 7:46 am

Categories: Gmail

Tags: Google Inc., Google Gmail, Vulnerability, Spam, E-mail Providers, Security, Internet, Garett Rogers

INSERT, the Information Security Research Team, has sucessfully created a proof of concept exploiting the “trust hierarchy” that exists between mail service providers. Taking advantage of the way Gmail forwards messages, the team was able to send 4000 messages in a short period of time from a single account without any countermeasures taken by Google.

Using Google as an open email relay is highly desierable for spammers because Gmail is trusted by most email providers — making messages sent though Gmail immune to most spam filtering.

Since the messages are delivered by Google’s own servers, an attack based on this flaw is able to bypass all spam filters that are based on the blacklist / whitelist concept. We were able to confirm that this vulnerability is indeed exploitable by crafting a proof of concept attack that allowed us to send forged email messages unrestrictedly through Google’s server infrastructure.

There has been no official comment by Google on this matter yet, but I’m hoping the problem will be resolved in short order. The vulnerability isn’t as serious as past ones that exposed contact lists, or let attackers steal cookies, but that shouldn’t stop it from being high priority.

For more details on this vulnerability, you can read the draft paper by INSERT here.

Garett RogersGarett Rogers is employed as a programmer for iQmetrix, which specializes in retail management software for the wireless industry. See his full profile and disclosure of his industry affiliations.


Email Garett Rogers

Subscribe to Googling Google via Email alerts or RSS.

  • Talkback
  • Most Recent of 7 Talkback(s)
Why people continue to use Google's services,
signature ?Loverock Davidson? informs us, ?is beyond [him]?. Along with much else, to judge from his appearances on this forum. Others more fortunate, however, do seem to possess the wherewithall to g... (Read the rest)
Posted by: mhenriday Posted on: 05/13/08 You are currently: a Guest | | Terms of Use
Not just Gmail! See Backscatter FYI  D. T. Schmitz | 05/09/08
Vital that this Gmail vulnerability is fixed,  mhenriday | 05/09/08
RE: Gmail can be used as  Loverock Davidson | 05/09/08
Pfffffffffft.  D. T. Schmitz | 05/09/08
Why people continue to use Google's services,  mhenriday | 05/13/08
Still a beta service  genericman | 05/10/08
if you try this in python, gmail stops you using it as a mail relay.  stevey_d | 05/10/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here