G-Archiver Steals Your Gmail Password
The nifty Gmail backup utility seems to have (possibly maliciously) collected the GMail logins of the programs users.
This was discovered when a developer named Dustin Brooks took a look at the code using a decompiler. He discovered a Gmail account name and password embedded in the source code. Brooks logged in and found over 1,700 emails all with user account information — with his own at the top. According to a story in Informationweek, he deleted the emails, changed the account password, and notified Google.
The developer of G-Archiver, says the code to collect users GMail logins was debug code that should have been stripped out of the shipping version and a patch will be available shortly.
Sneaky what some programmers are capable of.
