<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: GMail Vulnerable To Contact List Hijacking</title>
	<atom:link href="http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/</link>
	<description>Computer related blog</description>
	<pubDate>Fri, 25 Jul 2008 01:21:30 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: taj</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-54388</link>
		<dc:creator>taj</dc:creator>
		<pubDate>Tue, 18 Mar 2008 07:50:59 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-54388</guid>
		<description>hi there,
when ever i open a picture in my gmail account. i can still open that picture from the history even after loggin out from the Gmail. how do i stop it</description>
		<content:encoded><![CDATA[<p>hi there,<br />
when ever i open a picture in my gmail account. i can still open that picture from the history even after loggin out from the Gmail. how do i stop it</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: psychodeath</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-54062</link>
		<dc:creator>psychodeath</dc:creator>
		<pubDate>Wed, 12 Mar 2008 19:06:04 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-54062</guid>
		<description>I didn't get it... the 'exploit' is showing you info stored on your computer, and sent FROM a server TO your computer, but it is at no point sending private data from your PC to a third party... which is exactly what javascript is supposed to do... am I missing something here? is it so ridiculously simple to somehow send this client-side data somewhere that they didn't bother to show us how...?</description>
		<content:encoded><![CDATA[<p>I didn&#8217;t get it&#8230; the &#8216;exploit&#8217; is showing you info stored on your computer, and sent FROM a server TO your computer, but it is at no point sending private data from your PC to a third party&#8230; which is exactly what javascript is supposed to do&#8230; am I missing something here? is it so ridiculously simple to somehow send this client-side data somewhere that they didn&#8217;t bother to show us how&#8230;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 3Monkeys</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5518</link>
		<dc:creator>3Monkeys</dc:creator>
		<pubDate>Tue, 02 Jan 2007 22:26:18 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5518</guid>
		<description>Being a Linux user, I rarely have to worry about viruses, worms or spyware, though sometimes, as with the recent GMail hack, I do. Therefore, I subscribe to several computer security related RSS feeds and this one scrolled by earlier today, 'Happy New Year' Worm Gains Ground.</description>
		<content:encoded><![CDATA[<p>Being a Linux user, I rarely have to worry about viruses, worms or spyware, though sometimes, as with the recent GMail hack, I do. Therefore, I subscribe to several computer security related RSS feeds and this one scrolled by earlier today, &#8216;Happy New Year&#8217; Worm Gains Ground.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Bailey</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5465</link>
		<dc:creator>Alex Bailey</dc:creator>
		<pubDate>Tue, 02 Jan 2007 04:54:54 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5465</guid>
		<description>[quote comment="5460"]google ({
Success: false,
Errors: []
})[/quote]


Please see http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/</description>
		<content:encoded><![CDATA[<p>[quote comment="5460"]google ({<br />
Success: false,<br />
Errors: []<br />
})[/quote]</p>
<p>Please see <a href="http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/" rel="nofollow" target="_blank"></a><a href='http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/' target="_blank">cyber-know...now-fixed/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: merkelcellcancer</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5460</link>
		<dc:creator>merkelcellcancer</dc:creator>
		<pubDate>Tue, 02 Jan 2007 03:33:52 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5460</guid>
		<description>google ({
  Success: false,
  Errors: []
})</description>
		<content:encoded><![CDATA[<p>google ({<br />
  Success: false,<br />
  Errors: []<br />
})</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Uncle</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5428</link>
		<dc:creator>Uncle</dc:creator>
		<pubDate>Mon, 01 Jan 2007 20:58:58 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5428</guid>
		<description>Doesnt work on Vista.</description>
		<content:encoded><![CDATA[<p>Doesnt work on Vista.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yasser</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5397</link>
		<dc:creator>Yasser</dc:creator>
		<pubDate>Mon, 01 Jan 2007 16:09:38 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5397</guid>
		<description>Im pretty sure there will be more to come, its just a matter of time.</description>
		<content:encoded><![CDATA[<p>Im pretty sure there will be more to come, its just a matter of time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leion</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5396</link>
		<dc:creator>Leion</dc:creator>
		<pubDate>Mon, 01 Jan 2007 16:01:18 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5396</guid>
		<description>This is so cool!
I never close my gmail tab on my firefox. I think I need to change my habits a bit</description>
		<content:encoded><![CDATA[<p>This is so cool!<br />
I never close my gmail tab on my firefox. I think I need to change my habits a bit</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: crill</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5394</link>
		<dc:creator>crill</dc:creator>
		<pubDate>Mon, 01 Jan 2007 15:52:33 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5394</guid>
		<description>Works with Firefox only.
With IE7 and Opera it doesn't work.</description>
		<content:encoded><![CDATA[<p>Works with Firefox only.<br />
With IE7 and Opera it doesn&#8217;t work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Haochi</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5391</link>
		<dc:creator>Haochi</dc:creator>
		<pubDate>Mon, 01 Jan 2007 14:21:39 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5391</guid>
		<description>Hi, I am the one that found the bug.
First of all, I am sorry if it causes any inconvenience, or if it make you feel insecure of Gmail. I apologize.
The intention that I submitted to Digg was only to Google's attention to fix the bug, since I have contact them for hours, and they have failed to done so. (and the bug hasn't yet be fixed.)
I would have never ever think of any one would paste the clear code out, although it's encoded a little, but I know that it's easy to decode - Firefox comes with a cool feature. :)
Once again, sorry to anyone for any inconvenience and sorry for this new year's gift to Google.</description>
		<content:encoded><![CDATA[<p>Hi, I am the one that found the bug.<br />
First of all, I am sorry if it causes any inconvenience, or if it make you feel insecure of Gmail. I apologize.<br />
The intention that I submitted to Digg was only to Google&#8217;s attention to fix the bug, since I have contact them for hours, and they have failed to done so. (and the bug hasn&#8217;t yet be fixed.)<br />
I would have never ever think of any one would paste the clear code out, although it&#8217;s encoded a little, but I know that it&#8217;s easy to decode - Firefox comes with a cool feature. :)<br />
Once again, sorry to anyone for any inconvenience and sorry for this new year&#8217;s gift to Google.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Atfor Nohcud</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5387</link>
		<dc:creator>Atfor Nohcud</dc:creator>
		<pubDate>Mon, 01 Jan 2007 13:54:10 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5387</guid>
		<description>I can never understand why people have to use these lists and address books that you find in popular programs for novices such as outlook express.
You are looking for "trouble on the fairway".
Anything that is popularily used by default is bound to be a target.
Other than if you are running a big multi million dollar enterprise with tons of employees and committees why take the chance of being hit.
What is so hard about sending email manually ?</description>
		<content:encoded><![CDATA[<p>I can never understand why people have to use these lists and address books that you find in popular programs for novices such as outlook express.<br />
You are looking for &#8220;trouble on the fairway&#8221;.<br />
Anything that is popularily used by default is bound to be a target.<br />
Other than if you are running a big multi million dollar enterprise with tons of employees and committees why take the chance of being hit.<br />
What is so hard about sending email manually ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mesuot</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5380</link>
		<dc:creator>mesuot</dc:creator>
		<pubDate>Mon, 01 Jan 2007 13:22:26 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5380</guid>
		<description>[quote comment="5345"]&lt;code&gt;
function google(a){
var emails;
emails = ""
emails  = "" a.Body.Contacts[0].Email " "
for(i=1;i&#60;a&#62;" a.Body.Contacts[i].Email "";
}
emails  = ""
document.write(emails);
}

&lt;/code&gt;[/quote]

don't forget the plus signs, and it's working like a charm.</description>
		<content:encoded><![CDATA[<p>[quote comment="5345"]<code><br />
function google(a){<br />
var emails;<br />
emails = ""<br />
emails  = "" a.Body.Contacts[0].Email &#8221; &#8221;<br />
for(i=1;i&#60;a&#62;&#8221; a.Body.Contacts[i].Email &#8220;&#8221;;<br />
}<br />
emails  = &#8220;&#8221;<br />
document.write(emails);<br />
}</p>
<p></code>[/quote]</p>
<p>don&#8217;t forget the plus signs, and it&#8217;s working like a charm.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vibes</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5379</link>
		<dc:creator>Vibes</dc:creator>
		<pubDate>Mon, 01 Jan 2007 13:09:50 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5379</guid>
		<description>The cross scripting on gmail contact list work also on safari under mac os x...</description>
		<content:encoded><![CDATA[<p>The cross scripting on gmail contact list work also on safari under mac os x&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5378</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Mon, 01 Jan 2007 13:07:28 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5378</guid>
		<description>ouch, this is amazing and nothing can be done to fix this or is gmail using this to build their own mega contact list?</description>
		<content:encoded><![CDATA[<p>ouch, this is amazing and nothing can be done to fix this or is gmail using this to build their own mega contact list?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tiago</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5372</link>
		<dc:creator>Tiago</dc:creator>
		<pubDate>Mon, 01 Jan 2007 12:40:39 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/#comment-5372</guid>
		<description>Hi.. Could someone help out?
After opening http://googlified.com.googlepages.com/contactlist.htm
the email marked with  [........ </description>
		<content:encoded><![CDATA[<p>Hi.. Could someone help out?<br />
After opening <a href="http://googlified.com.googlepages.com/contactlist.htm" rel="nofollow" target="_blank"></a><a href='http://googlified.com.googlepages.com/contactlist.htm' target="_blank">googlified...ctlist.htm</a><br />
the email marked with  [&#8230;&#8230;..</p>
]]></content:encoded>
	</item>
</channel>
</rss>
