G-Archiver Steals Gmail Identities

Blog site Coding Horror recently recounted a security breach involving G-Archiver, a shareware Gmail backup utility that had been made available on many sites, including Cnet.com's popular download.com.

In an e-mail message to Coding Horror blogger Jeff Atwood, programmer Dustin Brooks described how he reverse-engineered G-Archiver after trying it out. He discovered that "apparent creator" John Terry had both hard-coded his own username and password for his Gmail account into the source code and coded the software to receive an e-mail with the user name and password for anybody else who used the utility to back up their Gmail data.

Atwood then logged into Terry's account using the information he'd uncovered and deleted a total of 1,777 e-mails with account information, including his own. Then he changed the password and security question to disable Terry's access and requested--as the logged-in John Terry--that Google delete the account.

Since publication of Brooks' discovery, the programmer has become a white hat hero to the hundreds of people who have posted comments to Atwood's original post. While Cnet has removed the utility from Download.com, G-Archiver is still available at a number of other download sites.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • academic building surrounded by clouds and glowing lightbulbs

    University of Pittsburgh Partners with AWS on Cloud Innovation Center

    The University of Pittsburgh is teaming up with Amazon Web Services to establish a new Cloud Innovation Center focused on health sciences and sports analytics.

  • glowing digital brain made of blue circuitry hovers above multiple stylized clouds of interconnected network nodes against a dark, futuristic background

    Report: 85% of Organizations Are Using Some Form of AI

    Eighty-five percent of organizations today are leveraging some form of AI, according to the latest State of AI in the Cloud 2025 report from Wiz. While AI's role in innovation and disruption continues to expand, security vulnerabilities and governance challenges remain pressing concerns.

  • illustration of a football stadium with helmet on the left and laptop with ed tech icons on the right

    The 2025 NFL Draft and Ed Tech Selection: A Strategic Parallel

    In the fast-evolving landscape of collegiate football, the NFL, and higher education, one might not immediately draw connections between the 2025 NFL Draft and the selection of proper educational technology for a college campus. However, upon closer examination, both processes share striking similarities: a rigorous assessment of needs, long-term strategic impact, talent or tool evaluation, financial considerations, and adaptability to a dynamic future.

  • Three cubes of noticeably increasing sizes are arranged in a straight row on a subtle abstract background

    A Sense of Scale

    Gardner Campbell explores the notion of scale in education and shares some of his own experience "playing with scale" — scaling up and/or scaling down — in an English course at VCU.