G-Archiver Steals Gmail Identities

Blog site Coding Horror recently recounted a security breach involving G-Archiver, a shareware Gmail backup utility that had been made available on many sites, including Cnet.com's popular download.com.

In an e-mail message to Coding Horror blogger Jeff Atwood, programmer Dustin Brooks described how he reverse-engineered G-Archiver after trying it out. He discovered that "apparent creator" John Terry had both hard-coded his own username and password for his Gmail account into the source code and coded the software to receive an e-mail with the user name and password for anybody else who used the utility to back up their Gmail data.

Atwood then logged into Terry's account using the information he'd uncovered and deleted a total of 1,777 e-mails with account information, including his own. Then he changed the password and security question to disable Terry's access and requested--as the logged-in John Terry--that Google delete the account.

Since publication of Brooks' discovery, the programmer has become a white hat hero to the hundreds of people who have posted comments to Atwood's original post. While Cnet has removed the utility from Download.com, G-Archiver is still available at a number of other download sites.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • Interface buttons of Generative AI tool

    Report: No Foolproof Method Exists for Detecting AI-Generated Media

    Microsoft has released a new research report warning that no single technology can reliably distinguish AI-generated content from authentic media, and that deepening reliance on any one method risks misleading the public.

  • abstract automation workflow

    Druva Adds Agentic Workflows, Deep Analysis Agents to DruAI Platform

    Druva has announced an expansion of its DruAI platform, introducing Deep Analysis Agents and new agentic workflow capabilities aimed at automating complex forensic, compliance, and operational investigations.

  • abstract generative AI technology

    Apple and Google Strike AI Deal to Bring Gemini Models to Siri

    Apple and Google announced they have embarked on a multiyear partnership that will put Google's Gemini models and cloud technology at the core of the next generation of Apple Foundation Models, a move that could help Apple accelerate long-promised upgrades to Siri while handing Google a high-profile distribution win on the iPhone.

  • A panel discussion from SXSW EDU 2025

    12 Ways to Dive into AI at SXSW EDU

    This March 9-12, the SXSW EDU Conference & Festival returns to Austin, TX, to celebrate innovation, experimentation, and learning across every stage of education.