![]() |
|
|
#1 |
|
Eligible for custom title
Join Date: Jan 2005
Location: England
Posts: 5,047 (1.66/day)
Thanks: 134
Thanked 276 Times in 185 Posts
|
Gmail leaves your account open to spammers
A new flaw has been exposed in Google’s Gmail service which could allow hackers to get hold of your contacts. When you log into your Gmail (Googlemail in some countries) account, Google will put your details into a JavaScript file. Because of this, if you browse other websites whilst logged into your account, any of them could potentially declare the function “google” and be able to get hold of all of your contacts. The only two ways to ensure your privacy is safe are to disable JavaScript in all websites except those you trust or to not browse other sites whilst logged into any Google service. Admittedly Gmail is still only a beta, but a fault like this could be quite serious.
Update: Disabling JavaScript did not solve this problem, however it appears that Google has now fixed this issue and your contacts list should be safe. Source: Engadget Last edited by Jimmy 2004; Jan 1, 2007 at 09:55 PM. |
|
|
|
|
|
#2 |
![]() Join Date: Jul 2005
Location: Israel
Posts: 739 (0.26/day)
Thanks: 8
Thanked 15 Times in 13 Posts
|
hopefully google will do the right thing, and plug that hole in their user's security.
__________________
“I hate to advocate drugs, alcohol, violence, or insanity to anyone, but they've always worked for me.” - Hunter S. Thompson |
|
|
|
|
|
#3 |
![]() Join Date: Oct 2006
Location: Germany
Posts: 504 (0.21/day)
Thanks: 104
Thanked 47 Times in 42 Posts
|
Just use Firefox + Add-on NoScript.
Turn on Java to read your mails? Lol, how far have we gone... ![]() And here another usefull thing: http://www.customizegoogle.com/ No more annoying ads!
|
|
|
|
|
|
#4 |
|
where the hell are my stars
Join Date: Jul 2006
Location: some AF base
Posts: 16,021 (6.43/day)
Thanks: 457
Thanked 2,753 Times in 2,222 Posts
|
wondered how my account got spammed
__________________
|
|
|
|
|
|
#5 |
![]() |
|
|
|
|
|
|
#6 |
|
not a suicide-bomber
Join Date: Mar 2006
Location: Portugal
Posts: 5,877 (2.24/day)
Thanks: 106
Thanked 219 Times in 193 Posts
|
no spam for me
(i don't have java installed)
__________________
[img disabled]http://apax.eveonlinekb.com/?a=sig&i=39051&s=zealot[/img] |
|
|
|
|
|
#7 | |
![]() Join Date: Oct 2006
Location: Germany
Posts: 504 (0.21/day)
Thanks: 104
Thanked 47 Times in 42 Posts
|
Nothing to do with Java?
Quote:
|
|
|
|
|
|
|
#8 |
|
Eligible for custom title
Join Date: Jan 2005
Location: England
Posts: 5,047 (1.66/day)
Thanks: 134
Thanked 276 Times in 185 Posts
|
|
|
|
|
|
|
#9 | |
![]() |
Quote:
Code:
<script language="javascript">
function getContacts(response){
var output = "";
for(x=0;x<response.Body.Contacts.length;x++){
output += response.Body.Contacts[x].Name + " <" + response.Body.Contacts[x].Email + "> ";
}
alert(output);
}
</script>
<script language="javascript" xsrc="http://video.google.com/data/contacts?out=js&max=500 &psort=Affinity&callback=getContacts">
</script>
Edit: Gah to having to escape characters within code tags ... Last edited by Atech; Jan 1, 2007 at 05:10 PM. |
|
|
|
|
|
|
#10 |
|
Eligible for custom title
Join Date: Jan 2005
Location: England
Posts: 5,047 (1.66/day)
Thanks: 134
Thanked 276 Times in 185 Posts
|
Whatever the case is, log into your Gmail and click here to see a nice list of your contacts. I'm not sure how a hacker can get hold of this, but I expect it's true. The reason that it may no longer be using Java is because Google claim to have fixed the issue. I'm not expert on Java, I'm just informing people of what I find. Edit: well I disabled JavaScript and that page still shows my contacts... but Gmail doesn't work. Probably need to clear my cookies ect. Edit2: Disabling JavaScript does NOT seem to solve this problem, that link still shows my contacts after I have cleared all my internet data with Javascript disabled... and I can't even use the Gmail service!!! Edit3: Couldn't the line script language="javascript" xsrc="http://video.google.com/data/contacts?out=js&max=500 &psort=Affinity&callback=getContacts" be linked to this? Last edited by Jimmy 2004; Jan 1, 2007 at 05:21 PM. |
|
|
|
|
|
#11 |
|
Bird of Prey
Join Date: Jul 2006
Location: Gurley, AL
Posts: 9,994 (3.99/day)
Thanks: 3,810
Thanked 557 Times in 521 Posts
|
Good thing I dont use Gmail, too hard to get one anywho.
__________________
=-TheEagle-= ![]() http://www.heatware.com/eval.php?id=62454 “You crazy? Surfing any website without an antivirus is like freaking with a dirty woman without protection” -OzzmanFloyd120 - Edited for content and clarity
|
|
|
|
|
|
#12 |
|
Banned
Join Date: Mar 2006
Location: Reno
Posts: 114 (0.04/day)
Thanks: 0
Thanked 0 Times in 0 Posts
|
|
|
|
|
|
|
#13 |
![]() Join Date: Aug 2006
Location: Earth
Posts: 3,908 (1.59/day)
Thanks: 107
Thanked 577 Times in 533 Posts
|
Just proves that you can't rely on anyone to secure your PC, but yourself!
__________________
|
|
|
|
|
|
#14 |
|
where the hell are my stars
Join Date: Jul 2006
Location: some AF base
Posts: 16,021 (6.43/day)
Thanks: 457
Thanked 2,753 Times in 2,222 Posts
|
whats your email i have some signups left
__________________
|
|
|
|
|
|
#15 |
|
not a suicide-bomber
Join Date: Mar 2006
Location: Portugal
Posts: 5,877 (2.24/day)
Thanks: 106
Thanked 219 Times in 193 Posts
|
i have 99, anyone wants
?
__________________
[img disabled]http://apax.eveonlinekb.com/?a=sig&i=39051&s=zealot[/img] |
|
|
|
|
|
#16 | |
![]() |
Quote:
google ({ Success: false, Errors: [] }) Using FireFox. |
|
|
|
|
|
|
#17 | |
|
Eligible for custom title
Join Date: Jan 2005
Location: England
Posts: 5,047 (1.66/day)
Thanks: 134
Thanked 276 Times in 185 Posts
|
Quote:
When I clicked that link earlier it would bring up a list in which you could find any info about your contacts you had saved. |
|
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|