G-Archiver is evil

On March 12, 2008, in google, reversing, security, by eugenekogan

This is a great lesson in why not to blindly trust random software that you find on the Internet. G-Archiver, a program created to help users locally save their Gmail messages, has a piece of code in it that sends your Gmail login and password to the author. You can see a scary screen shot of his inbox, since the guy had his own Gmail credentials hard coded right into the program, which was obviously discovered.

The details are at SANS ISC (source code) and Coding Horror (screen shot).

Related posts:

  1. iPhones have Eyes
  2. Taking advantage of UPnP to be evil
 

Comments are closed.