techPowerUp! Forums

Go Back   techPowerUp! Forums > www.techpowerup.com > News

Reply
 
Thread Tools
Old Jan 1, 2007, 11:08 AM   #1
Jimmy 2004
Eligible for custom title
 
Jimmy 2004's Avatar
 
Join Date: Jan 2005
Location: England
Posts: 5,047 (1.66/day)
Thanks: 134
Thanked 276 Times in 185 Posts
Send a message via MSN to Jimmy 2004

System Specs

Gmail leaves your account open to spammers

A new flaw has been exposed in Google’s Gmail service which could allow hackers to get hold of your contacts. When you log into your Gmail (Googlemail in some countries) account, Google will put your details into a JavaScript file. Because of this, if you browse other websites whilst logged into your account, any of them could potentially declare the function “google” and be able to get hold of all of your contacts. The only two ways to ensure your privacy is safe are to disable JavaScript in all websites except those you trust or to not browse other sites whilst logged into any Google service. Admittedly Gmail is still only a beta, but a fault like this could be quite serious.

Update: Disabling JavaScript did not solve this problem, however it appears that Google has now fixed this issue and your contacts list should be safe.

Source: Engadget

Last edited by Jimmy 2004; Jan 1, 2007 at 09:55 PM.
Jimmy 2004 is offline  
Reply With Quote
Old Jan 1, 2007, 01:04 PM   #2
spectre440
500 Posts
 
spectre440's Avatar
 
Join Date: Jul 2005
Location: Israel
Posts: 739 (0.26/day)
Thanks: 8
Thanked 15 Times in 13 Posts
Send a message via ICQ to spectre440 Send a message via MSN to spectre440

System Specs

hopefully google will do the right thing, and plug that hole in their user's security.
__________________
“I hate to advocate drugs, alcohol, violence, or insanity to anyone, but they've always worked for me.” - Hunter S. Thompson
spectre440 is offline  
Reply With Quote
Old Jan 1, 2007, 01:05 PM   #3
peach1971
500 Posts
 
peach1971's Avatar
 
Join Date: Oct 2006
Location: Germany
Posts: 504 (0.21/day)
Thanks: 104
Thanked 47 Times in 42 Posts

System Specs

Just use Firefox + Add-on NoScript.

Turn on Java to read your mails?
Lol, how far have we gone...

And here another usefull thing:
http://www.customizegoogle.com/

No more annoying ads!
peach1971 is offline  
Reply With Quote
Old Jan 1, 2007, 01:11 PM   #4
cdawall
where the hell are my stars
 
cdawall's Avatar
 
Join Date: Jul 2006
Location: some AF base
Posts: 16,021 (6.43/day)
Thanks: 457
Thanked 2,753 Times in 2,222 Posts
Send a message via AIM to cdawall Send a message via Yahoo to cdawall Send a message via Skype™ to cdawall

System Specs

wondered how my account got spammed
__________________
cdawall is offline  
Reply With Quote
Old Jan 1, 2007, 01:27 PM   #5
Atech
200 Posts
 
Join Date: Dec 2006
Posts: 259 (0.11/day)
Thanks: 3
Thanked 11 Times in 9 Posts

System Specs

Quote:
Originally Posted by peach1971 View Post
Turn on Java to read your mails?
Lol, how far have we gone...
This vulnerability has nothing to do with Java.
Atech is offline  
Reply With Quote
Old Jan 1, 2007, 02:12 PM   #6
pt
not a suicide-bomber
 
pt's Avatar
 
Join Date: Mar 2006
Location: Portugal
Posts: 5,877 (2.24/day)
Thanks: 106
Thanked 219 Times in 193 Posts
Send a message via MSN to pt

System Specs

no spam for me
(i don't have java installed)
pt is offline  
Reply With Quote
Old Jan 1, 2007, 02:43 PM   #7
peach1971
500 Posts
 
peach1971's Avatar
 
Join Date: Oct 2006
Location: Germany
Posts: 504 (0.21/day)
Thanks: 104
Thanked 47 Times in 42 Posts

System Specs

Nothing to do with Java?

Quote:
Google will put your details into a JavaScript file. Because of this, if you browse other websites whilst logged into your account, any of them could potentially declare the function “google” and be able to get hold of all of your contacts.
Sorry, I don´t get it, Atech.
peach1971 is offline  
Reply With Quote
Old Jan 1, 2007, 03:00 PM   #8
Jimmy 2004
Eligible for custom title
 
Jimmy 2004's Avatar
 
Join Date: Jan 2005
Location: England
Posts: 5,047 (1.66/day)
Thanks: 134
Thanked 276 Times in 185 Posts
Send a message via MSN to Jimmy 2004

System Specs

Quote:
Originally Posted by Atech View Post
This vulnerability has nothing to do with Java.
Well, from what I read when posting this story it was a JS (JavaScript) file that causes this problem, and you disable Java to protect yourself so it must link to Java
Jimmy 2004 is offline  
Reply With Quote
Old Jan 1, 2007, 05:05 PM   #9
Atech
200 Posts
 
Join Date: Dec 2006
Posts: 259 (0.11/day)
Thanks: 3
Thanked 11 Times in 9 Posts

System Specs

Quote:
Originally Posted by Jimmy 2004 View Post
Well, from what I read when posting this story it was a JS (JavaScript) file that causes this problem, and you disable Java to protect yourself so it must link to Java
Code:
<script language="javascript">
function getContacts(response){
var output = "";
for(x=0;x<response.Body.Contacts.length;x++){
output += response.Body.Contacts[x].Name + " <" + response.Body.Contacts[x].Email + "> ";
}
alert(output);
}
</script>

<script language="javascript" xsrc="http://video.google.com/data/contacts?out=js&max=500 &psort=Affinity&callback=getContacts">
</script>
No calls to the Java API there.

Edit: Gah to having to escape characters within code tags ...

Last edited by Atech; Jan 1, 2007 at 05:10 PM.
Atech is offline  
Reply With Quote
Old Jan 1, 2007, 05:09 PM   #10
Jimmy 2004
Eligible for custom title
 
Jimmy 2004's Avatar
 
Join Date: Jan 2005
Location: England
Posts: 5,047 (1.66/day)
Thanks: 134
Thanked 276 Times in 185 Posts
Send a message via MSN to Jimmy 2004

System Specs

Quote:
Originally Posted by Atech View Post
No calls to the Java API there.

Whatever the case is, log into your Gmail and click here to see a nice list of your contacts. I'm not sure how a hacker can get hold of this, but I expect it's true. The reason that it may no longer be using Java is because Google claim to have fixed the issue. I'm not expert on Java, I'm just informing people of what I find.

Edit: well I disabled JavaScript and that page still shows my contacts... but Gmail doesn't work. Probably need to clear my cookies ect.

Edit2: Disabling JavaScript does NOT seem to solve this problem, that link still shows my contacts after I have cleared all my internet data with Javascript disabled... and I can't even use the Gmail service!!!

Edit3: Couldn't the line
script language="javascript" xsrc="http://video.google.com/data/contacts?out=js&max=500 &psort=Affinity&callback=getContacts"
be linked to this?

Last edited by Jimmy 2004; Jan 1, 2007 at 05:21 PM.
Jimmy 2004 is offline  
Reply With Quote
Old Jan 1, 2007, 08:03 PM   #11
WarEagleAU
Bird of Prey
 
WarEagleAU's Avatar
 
Join Date: Jul 2006
Location: Gurley, AL
Posts: 9,994 (3.99/day)
Thanks: 3,810
Thanked 557 Times in 521 Posts
Send a message via AIM to WarEagleAU Send a message via Yahoo to WarEagleAU

System Specs

Good thing I dont use Gmail, too hard to get one anywho.
__________________
=-TheEagle-=



http://www.heatware.com/eval.php?id=62454
“You crazy? Surfing any website without an antivirus is like freaking with a dirty woman without protection” -OzzmanFloyd120
- Edited for content and clarity
WarEagleAU is offline  
Reply With Quote
Old Jan 1, 2007, 08:07 PM   #12
mout12
Banned
 
mout12's Avatar
 
Join Date: Mar 2006
Location: Reno
Posts: 114 (0.04/day)
Thanks: 0
Thanked 0 Times in 0 Posts

Quote:
Originally Posted by WarEagleAU View Post
Good thing I dont use Gmail, too hard to get one anywho.
no. Go to mail.google.com, click 'SIGN UP', then enter your mobile phone number, and they'll send you a password via text message to your phone number. you'll have an account.
mout12 is offline  
Reply With Quote
Old Jan 1, 2007, 08:35 PM   #13
Namslas90
3500 Posts
 
Join Date: Aug 2006
Location: Earth
Posts: 3,908 (1.59/day)
Thanks: 107
Thanked 577 Times in 533 Posts

System Specs

Just proves that you can't rely on anyone to secure your PC, but yourself!
__________________
Namslas90 is offline  
Reply With Quote
Old Jan 1, 2007, 09:17 PM   #14
cdawall
where the hell are my stars
 
cdawall's Avatar
 
Join Date: Jul 2006
Location: some AF base
Posts: 16,021 (6.43/day)
Thanks: 457
Thanked 2,753 Times in 2,222 Posts
Send a message via AIM to cdawall Send a message via Yahoo to cdawall Send a message via Skype™ to cdawall

System Specs

Quote:
Originally Posted by WarEagleAU View Post
Good thing I dont use Gmail, too hard to get one anywho.
whats your email i have some signups left
__________________
cdawall is offline  
Reply With Quote
Old Jan 1, 2007, 09:20 PM   #15
pt
not a suicide-bomber
 
pt's Avatar
 
Join Date: Mar 2006
Location: Portugal
Posts: 5,877 (2.24/day)
Thanks: 106
Thanked 219 Times in 193 Posts
Send a message via MSN to pt

System Specs

i have 99, anyone wants ?
pt is offline  
Reply With Quote
Old Jan 1, 2007, 09:28 PM   #16
Bull Dog
75 Posts
 
Bull Dog's Avatar
 
Join Date: Jan 2006
Posts: 156 (0.06/day)
Thanks: 3
Thanked 17 Times in 11 Posts

System Specs

Quote:
Originally Posted by Jimmy 2004 View Post
Whatever the case is, log into your Gmail and click here to see a nice list of your contacts. I'm not sure how a hacker can get hold of this, but I expect it's true. The reason that it may no longer be using Java is because Google claim to have fixed the issue. I'm not expert on Java, I'm just informing people of what I find.
...snip.
That link doesn't work for me.....meaning that when I am logged into my Gmail acct, and when I click on the link all I get is this:
google ({
Success: false,
Errors: []
})

Using FireFox.
Bull Dog is offline  
Reply With Quote
Old Jan 1, 2007, 09:53 PM   #17
Jimmy 2004
Eligible for custom title
 
Jimmy 2004's Avatar
 
Join Date: Jan 2005
Location: England
Posts: 5,047 (1.66/day)
Thanks: 134
Thanked 276 Times in 185 Posts
Send a message via MSN to Jimmy 2004

System Specs

Quote:
Originally Posted by Bull Dog View Post
That link doesn't work for me.....meaning that when I am logged into my Gmail acct, and when I click on the link all I get is this:
google ({
Success: false,
Errors: []
})

Using FireFox.
Me too, I think they must've fixed it. I've updated the newspost again.

When I clicked that link earlier it would bring up a list in which you could find any info about your contacts you had saved.
Jimmy 2004 is offline  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT. The time now is 02:29 PM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts