Israeli IT Expert Identifies Gmail Flaw, Prevents Hackers From Capturing Email Addresses
Error: Contact form not found.
by Joshua Levitt
Israeli computers expert Oren Hafif was featured this week in Wired Magazine and the Daily Mail for helping to save users of Google’s Gmail program from being exposed to hackers.
On his blog, Hafif explained how a sharing feature of Gmail allows a user to ‘delegate’ access to their account.
By adjusting the web address, Hafif found it was possible to reveal other users’ email addresses. By automating the character changes with a software program called DirBuster, he was able to collect 37,000 Gmail addresses in two hours.
Hafif said the flaw could have left users vulnerable to spam, phishing or password-guessing attacks, but it would not have exposed their passwords.
Hafif, a Tel Aviv-based penetration tester for security firm Trustwave, said it took Google another month after his report to fix the bug. He was paid $500 for the tip.
Western Conservatism Is Searching for Its Soul — But Is It Listening to the Jews?
Iran and US Step Up Attacks and Threaten to Escalate
Hezbollah Rejects US-Brokered Israel-Lebanon Security Deal as ‘Surrender’
Tanker Struck in Hormuz as Iran, US Trade Attacks in Worst Escalation Since Peace Deal
US Strikes Iran Following Attack on Cargo Ship in Strait of Hormuz
British Man Admits Threatening to ‘Kill Jewish Schoolchildren’ Amid Rising Antisemitism in London
Turkey Expands Online Censorship, Silences Dissent as Erdogan Tightens Grip on Power
Plurality of Americans Believe US ‘Too Supportive’ of Israel, Poll Finds
Israel, Lebanon Sign Initial Agreement After US-Mediated Talks
Trump Chides Iran for Ship Attack After Tehran Insists on Control of Strait of Hormuz






Iran and US Step Up Attacks and Threaten to Escalate
Hezbollah Rejects US-Brokered Israel-Lebanon Security Deal as ‘Surrender’
Tanker Struck in Hormuz as Iran, US Trade Attacks in Worst Escalation Since Peace Deal
Western Conservatism Is Searching for Its Soul — But Is It Listening to the Jews?



