VaRuAs
Famous Hero
Only The Chosen Will Survive
|
posted January 04, 2007 03:40 AM |
|
|
GMail Hacked: Your Whole Contact List Can be Stolen
GMail Hacked: Visit ANY Website, and Your Whole Contact List Can be Stolen
Quote: GMail Vulnerable To Contact List Hijacking
Using a form of cross scripting, it becomes easy to steal a GMail user’s contact list if they visit a certain type of website. The only condition is you have to be logged in to GMail at the time of the attack. GMail is setup to store your contact list in javascript files, which is the core problem. If you log into your GMail account, and click here, you’ll see your contact’s details, along with their email. I've tried the hack on IE7, Opera, and Firefox; it appears to be working on all three. To see a demonstration of the attack, login to your GMail account and go to this website. I don’t know for sure if the list is being saved or not, so browse at your own risk. According to the website they aren’t saving the data.
Source: http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/
____________
Quote
Aculias: WHy did Minnie Mouse break up with Mickey?
Because he was F^%$^$g Goofey.
quote
|
|