Hackers expose holes in GMail

In the past few days, there have been multiple disclosures of security vulnerabilities in a wide range of Google products, including a persistent e-mail theft issue affecting the widely used GMail service.
The unpatched GMail bug is particularly nasty because of the way the exploit works without any user action and the fact that it’s difficult for the average GMail user to know that e-mails are being stolen.
The victim visits a page while being logged into GMail. Upon execution, the page performs a multipart/form-data POST to one of...
» Read the rest of the post





