Home > G-Archiver Steals Gmail Identities

News

G-Archiver Steals Gmail Identities

3/13/2008

Blog site Coding Horror recently recounted a security breach involving G-Archiver, a shareware Gmail backup utility that had been made available on many sites, including Cnet.com's popular download.com.

In an e-mail message to Coding Horror blogger Jeff Atwood, programmer Dustin Brooks described how he reverse-engineered G-Archiver after trying it out. He discovered that "apparent creator" John Terry had both hard-coded his own username and password for his Gmail account into the source code and coded the software to receive an e-mail with the user name and password for anybody else who used the utility to back up their Gmail data.

Atwood then logged into Terry's account using the information he'd uncovered and deleted a total of 1,777 e-mails with account information, including his own. Then he changed the password and security question to disable Terry's access and requested--as the logged-in John Terry--that Google delete the account.

Since publication of Brooks' discovery, the programmer has become a white hat hero to the hundreds of people who have posted comments to Atwood's original post. While Cnet has removed the utility from Download.com, G-Archiver is still available at a number of other download sites.


Dian Schaffhauser is a writer who covers technology and business. Send your higher education technology news to her at dian@dischaffhauser.com.

Cite this Site

Dian Schaffhauser, "G-Archiver Steals Gmail Identities," Campus Technology, 3/13/2008, http://www.campustechnology.com/article.aspx?aid=59719

copy text (above) for proper citation



Recommended Reading
  • Sun, Stanford Working To Archive History

    In May in San Francisco, experts from leading universities, libraries, and research institutions around the world met as part of an ongoing effort to address a pressing issue: archiving the world's history, right up to today.

  • The Quilt Coalition Rolls Out XO Communications for High-Capacity Network Services

    The Quilt, a coalition of 28 regional network organizations, has added XO Communications Services to its authorized vendor list. The Quilt represents 200 universities and thousands of other educational institutions across the United States. With this new relationship, Quilt members can purchase XO's high-speed IP transit and network transport services at competitive rates.

  • Wimba Classroom 5.2 Expands Classroom Capture Support, Adds MP3 Downloads

    At the NECC 2008 conference in Texas this week, Wimba launched a new version of Wimba Classroom, the virtual classroom component of the company's Collaboration Suite. The new 5.2 release expands options for classroom capture and adds a variety of other functional and ease of use features.

  • Automation Chimera: Education Is Not Management

    The lure of automating workflow online so human intervention is minimized is continually reinforced in the minds of higher education administrators by examples of automated campus systems such as financials, student information systems, and other enterprise systems. But what's good for management is not always good for learning.

  • Cognos Releases BI Software for Linux-based IBM System z Mainframe

    Cognos, which IBM acquired in January, has released an update to its business intelligence software that will run on the Linux operating system on IBM System z mainframes. IBM Cognos 8 BI was being developed by the two companies prior to the acquisition, but assimilation of Cognos into IBM accelerated development.

  • Facebook and Collegiality: A Serendipitous Social Niche

    Facebook is a way to greet a colleague as if she or he is on your own campus: a wave at a distance, a hello at the corner burrito place, a honk as you both leave the campus parking lot. Informal collegiality has been extended over the miles.