G-Archiver Steals Gmail Identities

Blog site Coding Horror recently recounted a security breach involving G-Archiver, a shareware Gmail backup utility that had been made available on many sites, including Cnet.com's popular download.com.

In an e-mail message to Coding Horror blogger Jeff Atwood, programmer Dustin Brooks described how he reverse-engineered G-Archiver after trying it out. He discovered that "apparent creator" John Terry had both hard-coded his own username and password for his Gmail account into the source code and coded the software to receive an e-mail with the user name and password for anybody else who used the utility to back up their Gmail data.

Atwood then logged into Terry's account using the information he'd uncovered and deleted a total of 1,777 e-mails with account information, including his own. Then he changed the password and security question to disable Terry's access and requested--as the logged-in John Terry--that Google delete the account.

Since publication of Brooks' discovery, the programmer has become a white hat hero to the hundreds of people who have posted comments to Atwood's original post. While Cnet has removed the utility from Download.com, G-Archiver is still available at a number of other download sites.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • From Fire TV to Signage Stick: University of Utah's Digital Signage Evolution

    Jake Sorensen, who oversees sponsorship and advertising and Student Media in Auxiliary Business Development at the University of Utah, has navigated the digital signage landscape for nearly 15 years. He was managing hundreds of devices on campus that were incompatible with digital signage requirements and needed a solution that was reliable and lowered labor costs. The Amazon Signage Stick, specifically engineered for digital signage applications, gave him the stability and design functionality the University of Utah needed, along with the assurance of long-term support.

  • Abstract geometric shapes including hexagons, circles, and triangles in blue, silver, and white

    Google Launches Its Most Advanced AI Model Yet

    Google has introduced Gemini 2.5 Pro Experimental, a new artificial intelligence model designed to reason through problems before delivering answers, a shift that marks a major leap in AI capability, according to the company.

  • Training the Next Generation of Space Cybersecurity Experts

    CT asked Scott Shackelford, Indiana University professor of law and director of the Ostrom Workshop Program on Cybersecurity and Internet Governance, about the possible emergence of space cybersecurity as a separate field that would support changing practices and foster future space cybersecurity leaders.

  • Two stylized glowing spheres with swirling particles and binary code are connected by light beams in a futuristic, gradient space

    New Boston-Based Research Center to Advance Quantum Computing with AI

    NVIDIA is establishing a research hub dedicated to advancing quantum computing through artificial intelligence (AI) and accelerated computing technologies.