blog.world3.net

G-Archiver stealing login details – a cautionary tale

Today’s Coding Horror blog entry is rather disturbing, but not particularly surprising. In short, Dustin Brooks downloaded the free G-Archiver program to backup his gmail account. It didn’t work exactly as he wanted, so he used a .NET disassembler to check the source code. Amazingly, not only were the author’s login details hard coded in, but the program was sending an email with the login details of everyone who used the program to his account!

This kind of security breach is very hard to defend against, because no anti-malware software will detect it. Your firewall will need to allow the program access in order to backup your account. It’s not a virus, and even heuristic scanning probably wouldn’t see much wrong with a program sending emails too. I suppose it would be nice to at least warn the user that the program can do that.

The company that produces the software looks pretty dodgy. I suppose the lesson here is stick to open source software, where it’s hard to get away with that sort of thing.

This entry was written by mojo, posted on 08/03/2008 at 12:25, filed under Uncategorized. Bookmark the permalink. Follow any comments here with the RSS feed for this post. Post a comment or leave a trackback: Trackback URL.
« Defence against capturing passwords from memory
UK ISPs allowing Phorm fraudsters to track everyone! »

One Trackback

  1. By Avira Labs fail to identify malware, even when the analysis is done for them « Mojo’s Random Musings on 10/03/2008 at 18:16

    [...] fail to identify malware, even when the analysis is done for them As a follow-up to  to my blog post about g-archiver, I submitted g-archiver to Avira Labs (makers of Anti-Vir) for analysis so it can be added to their [...]

Post a Comment

Your email is never shared. Required fields are marked *

*
*

たとえ溺れても梦はゆめでしかない
  •  

    March 2008
    M T W T F S S
    « Feb   Apr »
     12
    3456789
    10111213141516
    17181920212223
    24252627282930
    31  
  • Meta

    • Log in
    • Entries RSS
    • Comments RSS
    • WordPress.org
  • Categories

    • audio (1)
    • avr (20)
    • BBC (1)
    • electronics (29)
    • genius (4)
    • hardware (22)
    • idiots (39)
    • Internet (21)
    • law (20)
    • microcontrollers (12)
    • networking (17)
    • politics (29)
    • privacy (19)
    • Retro Adapter (5)
    • security (17)
    • software (32)
    • Uncategorized (18)
    • windows (25)
  • Archives

    • February 2012
    • January 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • July 2011
    • June 2011
    • May 2011
    • March 2011
    • January 2011
    • December 2010
    • November 2010
    • August 2010
    • July 2010
    • June 2010
    • May 2010
    • April 2010
    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • November 2005
  • Links:

    Main site: world3.net

    Electronics: denki.world3.net

WordPress | Sandbox