Google embarrassed by phishing demo

Fake Gmail site served by Google itself.

Web search and service behemoth Google has had its security credibility hit this weekend, after a site was set up on its servers spoofing its own GoogleMail service, and demonstrating how the system could be used to gather personal details.

Advertise on www.virusbtn.com

The site was set up via the Google Public Service Search system, designed for public bodies and educational institutions, and provided an official-looking interface described as 'Gmail plus'. When users entered GoogleMail login details, they were displayed on the screen with a message making it clear they had been tricked into revealing them.

The page (here) was reported to Google by the creator soon after it was set up, and has now been removed; visiting it now displays a page warning that visiting it resembles the actions of a malware-infected computer.

18 September 2006

Tags: virus  

 del.icio.us  digg this! digg this

Quick Links

Poll
Does your company allow you to use a personal laptop/mobile device to access company resources?
Yes, it's allowed
Yes, it's actively encouraged
No
I don't know
Leave a comment
View 1 comment

Jobs Recruit Sidebar

Jobs
In Virus Bulletin's jobs pages among others:

Virus Bulletin currently has 225,202 registered users.