Teen Blogger Discovers GMail Javascript Vulnerability

Teen Blogger Discovers GMail Javascript Vulnerability

A 14 year old blogger (aren’t all 14 year olds bloggers?) recently discovered a hole in Google Gmail which allows automatic javascript execution when someone is using the email preview function.

From Ph3rny’s Blogspot hosted Blogger Blog :

I was recently attempting to mail some javascript code from my yahoo account to my gmail when I came across this vulnerability.

Apparently javascript will run if it is withing the preview of the message.

I only tested this sending from a yahoo account. Sending gmail to gmail appears to filter this out.

This is what the message has to compose of

* A short subject to increase the ammount of code to run

* A short bit of text in the body so that the code isn’t treated as quoted text

* And your code

My simple test was : Subject: a Body: asdfasdf

Here is a screen: http://www.ipnow.org/vulnerability.png

This vulnerability could be used to gather email addresses. Or even possibly to compromise the account.

Google’s Gmail has since addressed and fixed the flaw :

“We learned of a minor security flaw in Gmail a little while ago and worked quickly to fix the problem, which has now been resolved. We encourage all vulnerability reporters to follow responsible disclosure practices and notify vendors first before making the vulnerability public.”

Written By:
PG

| Search Engine Journal | @lorenbaker

Loren Baker is the founding editor/creator of Search Engine Journal and remains an advisor and Editor In Chief to this publication.

More Posts By

Comments

  1. Laura says:

    My GMail’s are going to my other friend and all mine are going to only one person? Could you help me with this?

  2. Laura says:

    My email’s are going to only one person. What should I do?

  3. 5p0f3r says:

    alert(document.location=’http:/www.google.com’);alert(“jj”)