Since I am a serious developer and a designer I understand nothing is completely safe, everything can be hacked. Considering the Anonymous Threat to Facebook, I am nobody. I do not have access to inside information on the latest gadget or consumer electronics. Which means that someone has access to Google accounts randomly or this is a serious issue with Google.
Every time you access anything on Gmail, even an image, your browser also sends your cookie to the website. This makes it possible for an attacker sniffing traffic on the network to insert an image served from http://mail.google.com and force your browser to send the cookie file, thus getting your session ID. Once this happens the attacker can log in to the account without the need of a password. People checking their e-mail from public wireless hotspots are obviously more likely to get attacked than the ones using secure wired networks.
The Cracker is either located in Italy or using a VPN account to look like the hack is coming from Italy. I was expecting the first Google hack to come from Nigeria, who wouldn’t.
More information on 212.239.17.140
IP Address: 212.239.17.140
Hostname: global.be3a.com
IP Country: Italy
IP Country Code: ITA
IP Continent: Europe
IP Region: Emilia-Romagna
Guessed City: Parma
The ip address 212.239.17.140 has been recorded as a spammers/BOTNET ip. If you have had a member sign up with this address you may want to consider contacting them, and possibly banning them from your site.
What Google Can Do
- Stop Cookies
- If Google can easily see if my account has been accessed outside the ‘norm’, so why not have a 2nd tier for password protection. Just like a bank, have me setup a second password or image check.
What You Can Do
- Change your password every six (6) months
- Never share your password with anyone, not even a relative or colleague. If another person has your password, they can, for all computer purposes, be you.
- Use VPN when using WiFi at Wifi Hotspots. Check out the IBVPN review that I currently use.
- Different password for each account. Using the same email for all your online accounts is quite dangerous.
- Whenever possible, use at least 14 characters or more.
- The greater the variety of characters in your password, the better.
- Use the entire keyboard, not just the letters and characters you use or see most often.
- Never use a credit card or your debit card. Use a Paypal account or PayPal debit/credit card. Paypal will protect you against scams and online transactions.




