<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>E-Z Life &#187; Gmail</title>
	<atom:link href="http://www.ezrahill.co.uk/tag/gmail/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ezrahill.co.uk</link>
	<description>- Daily Diary of Ezra Hill</description>
	<lastBuildDate>Wed, 08 Sep 2010 11:49:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Gmail Exploit Aids Domain Hijack</title>
		<link>http://www.ezrahill.co.uk/2007/12/31/gmail-exploit-aids-domain-hijack/</link>
		<comments>http://www.ezrahill.co.uk/2007/12/31/gmail-exploit-aids-domain-hijack/#comments</comments>
		<pubDate>Mon, 31 Dec 2007 07:46:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Gmail]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://www.ezrahill.co.uk/2007/12/31/gmail-exploit-aids-domain-hijack/</guid>
		<description><![CDATA[&#160; Web designer David Airey has succeeded in recovering his domain after hackers exploited flaws in Gmail to trick his hosts into authorising a fraudulent transfer. Airey&#8217;s woes began when he took his girlfriend for a month-long holiday to India on 21 November, a trip he mentioned in his blog. The holiday was a break [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-6405211419695752";
google_ad_slot = "1232232141";
google_ad_width = 468;
google_ad_height = 60;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>&#160;</p>
<blockquote><p>Web designer David Airey has succeeded in recovering his domain after hackers exploited flaws in Gmail to trick his hosts into authorising a fraudulent transfer.</p>
<p>Airey&#8217;s woes began when he took his girlfriend for a month-long holiday to India on 21 November, a trip he mentioned in his blog. The holiday was a break from work and he only occasionally checked his emails.</p>
<p>All seemed well until shortly before his return when Airey received an email from a friend informing him that his website, Davidairey.com, had &quot;disappeared&quot;.</p>
<p>At first Airey thought he&#8217;d made a mistake and allowed his domain name to expire and a domain poacher had snapped it up before he got the chance to renew it. Subsequent digging revealed a darker truth: hackers had posted a bogus transfer request on his web host support panel the day Airey left for India.</p>
<p>This, alongside an attack on a Gmail account run by Airey, allowed them to seize his domain and hold it for ransom. Initially crooks demanded $650 before dropping their offer down to $250.</p>
<p>Airey&#8217;s host, ICDSoft, were unable to reverse the transfer. The transfer request was initially sent to Airey&#8217;s Gmail account but forwarded to crooks after they used an exploit to forward the email to a third-party account. Gmail has since fixed the <a href="http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/">flaw</a> but Airey says that users would still be wise to check their account settings to verify that they too haven&#8217;t been hit by the hack.</p>
<p>Recovering the domain through legal action would eat up far more in lawyer&#8217;s fees, perhaps a minimum of $1,500, and might take months. During that time Airey would also lose passing trade that the domain brought in. In the meantime Airey has established an alternative Davidairey.co.uk website.</p>
</blockquote>
<p><a href="http://www.theregister.co.uk/2007/12/28/site_hijack_gmail_exploit/">Gmail exploit aids domain hijack</a></p>
<div class="wlWriterSmartContent" id="scid:B3E14793-948F-49af-A347-D19C374A7C4F:f3992701-5c64-4aed-9262-46fb1a6c8eef" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px">
<p><script type="text/javascript"><!--
digg_url = "http://digg.com/security/Gmail_Exploit_Aids_Domain_Hijack";
digg_title = "Gmail Exploit Aids Domain Hijack";
digg_bodytext = "&nbsp;";
digg_topic = "security";
//--></script> <script src="http://digg.com/tools/diggthis.js" type="text/javascript"></script> </div>
<p><script type="text/javascript"><!--
google_ad_client = "pub-6405211419695752";
google_ad_slot = "1984834111";
google_ad_width = 300;
google_ad_height = 250;
//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<!-- Social Bookmarks BEGIN -->
<div class="social_bookmark">
<a title="Click me to see the sites." href="#" onclick="$$('div.d3505').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;"><strong><em>Share</em></strong></a>
<br />
<div class="d3505" style="overflow:hidden">
<br />
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F&amp;title=Gmail+Exploit+Aids+Domain+Hijack" rel="nofollow" title="Add to&nbsp;Del.icio.us"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/delicious.png" title="Add to&nbsp;Del.icio.us" alt="Add to&nbsp;Del.icio.us" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F&amp;title=Gmail+Exploit+Aids+Domain+Hijack" rel="nofollow" title="Add to&nbsp;digg"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/digg.png" title="Add to&nbsp;digg" alt="Add to&nbsp;digg" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F" rel="nofollow" title="Add to&nbsp;Facebook"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/facebook.png" title="Add to&nbsp;Facebook" alt="Add to&nbsp;Facebook" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F&amp;title=Gmail+Exploit+Aids+Domain+Hijack" rel="nofollow" title="Add to&nbsp;Google Bookmarks"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/google.png" title="Add to&nbsp;Google Bookmarks" alt="Add to&nbsp;Google Bookmarks" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F&amp;title=Gmail+Exploit+Aids+Domain+Hijack" rel="nofollow" title="Add to&nbsp;Stumble Upon"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/stumbleupon.png" title="Add to&nbsp;Stumble Upon" alt="Add to&nbsp;Stumble Upon" /></a>
<a onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://twitter.com/home/?status=Check+out+Gmail+Exploit+Aids+Domain+Hijack+@+http%3A%2F%2Fwww.ezrahill.co.uk%2F2007%2F12%2F31%2Fgmail-exploit-aids-domain-hijack%2F" rel="nofollow" title="Add to&nbsp;Twitter"><img class="social_img" src="http://www.ezrahill.co.uk/wp-content/plugins/social-bookmarks/images/twitter.png" title="Add to&nbsp;Twitter" alt="Add to&nbsp;Twitter" /></a>
<br />
<a style="font-size:90%;text-align: right; " title="Click me to hide the sites." href="#" onclick="$$('div.d3505').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;">Hide Sites</a>
</div>
</div>
<!-- Social Bookmarks END -->
]]></content:encoded>
			<wfw:commentRss>http://www.ezrahill.co.uk/2007/12/31/gmail-exploit-aids-domain-hijack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
