<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: GMail&#8217;s Flaw Is Now Fixed</title>
	<atom:link href="http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/</link>
	<description>Computer related blog</description>
	<pubDate>Wed, 20 Aug 2008 17:46:41 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: Alex Bailey</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5514</link>
		<dc:creator>Alex Bailey</dc:creator>
		<pubDate>Tue, 02 Jan 2007 22:07:31 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5514</guid>
		<description>[quote comment="5474"]The bug has NOT been fixed..Try checking the same URL with the out param modified

http://docs.google.com/data/contacts?out=xml&#38;show=ALL&#38;psort=Affinity&#38;callback=google&#38;max=99999

now your address book comes out in a xml format..[/quote]

The output is XML.  You can't declare the function "google" with XML.

[quote]
It is upsetting that some people(not us) feel the need to hack into other peopleâ€™s accounts.
[/quote]
Had nothing to do with getting into people's accounts.  It was to steal their contact list.</description>
		<content:encoded><![CDATA[<p>[quote comment="5474"]The bug has NOT been fixed..Try checking the same URL with the out param modified</p>
<p><a href="http://docs.google.com/data/contacts?out=xml&amp;show=ALL&amp;psort=Affinity&amp;callback=google&amp;max=99999" rel="nofollow" target="_blank"></a><a href='http://docs.google.com/data/contacts?out=xml&amp;show=ALL&amp;psort=Affinity&amp;callback=google&amp;max=99999' target="_blank">docs.googl...;max=99999</a></p>
<p>now your address book comes out in a xml format..[/quote]</p>
<p>The output is XML.  You can&#8217;t declare the function &#8220;google&#8221; with XML.</p>
<p>[quote]<br />
It is upsetting that some people(not us) feel the need to hack into other peopleâ€™s accounts.<br />
[/quote]<br />
Had nothing to do with getting into people&#8217;s accounts.  It was to steal their contact list.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jim</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5512</link>
		<dc:creator>jim</dc:creator>
		<pubDate>Tue, 02 Jan 2007 21:37:54 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5512</guid>
		<description>It is upsetting that some people(not us) feel the need to hack into other people's accounts.</description>
		<content:encoded><![CDATA[<p>It is upsetting that some people(not us) feel the need to hack into other people&#8217;s accounts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: specialk</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5501</link>
		<dc:creator>specialk</dc:creator>
		<pubDate>Tue, 02 Jan 2007 17:15:15 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5501</guid>
		<description>Yeah, Google needs to get on this quickly. The exploit is still going strong and now the little guys (spammers and hackers) will now have plenty more people to send kind New Years greetings!

Fix It Google!

-specialk</description>
		<content:encoded><![CDATA[<p>Yeah, Google needs to get on this quickly. The exploit is still going strong and now the little guys (spammers and hackers) will now have plenty more people to send kind New Years greetings!</p>
<p>Fix It Google!</p>
<p>-specialk</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5499</link>
		<dc:creator>Jordan</dc:creator>
		<pubDate>Tue, 02 Jan 2007 15:51:52 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5499</guid>
		<description>But if the output comes back in XML format how do you get the exploit to still work?  You won't be able to access the script content because of the browser's cross-domain policies, right?  The only reason you could before was because it was loaded as javascript.  Or am I misunderstanding?  I'm pretty sure this is why folks use JSON and cross-domain proxies</description>
		<content:encoded><![CDATA[<p>But if the output comes back in XML format how do you get the exploit to still work?  You won&#8217;t be able to access the script content because of the browser&#8217;s cross-domain policies, right?  The only reason you could before was because it was loaded as javascript.  Or am I misunderstanding?  I&#8217;m pretty sure this is why folks use JSON and cross-domain proxies</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: z</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5492</link>
		<dc:creator>z</dc:creator>
		<pubDate>Tue, 02 Jan 2007 13:42:15 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5492</guid>
		<description>Unless I'm mistaken this is just a page that returns some XML.  Since it's not returning javasript you can't include it in your page header.  So problem solved.</description>
		<content:encoded><![CDATA[<p>Unless I&#8217;m mistaken this is just a page that returns some XML.  Since it&#8217;s not returning javasript you can&#8217;t include it in your page header.  So problem solved.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nikolai</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5485</link>
		<dc:creator>nikolai</dc:creator>
		<pubDate>Tue, 02 Jan 2007 11:46:24 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5485</guid>
		<description>No, you were right the first time. The XML output can't be exploited</description>
		<content:encoded><![CDATA[<p>No, you were right the first time. The XML output can&#8217;t be exploited</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gent</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5478</link>
		<dc:creator>Gent</dc:creator>
		<pubDate>Tue, 02 Jan 2007 10:13:35 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5478</guid>
		<description>th0r is right, exploit still works.</description>
		<content:encoded><![CDATA[<p>th0r is right, exploit still works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: th0r</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5474</link>
		<dc:creator>th0r</dc:creator>
		<pubDate>Tue, 02 Jan 2007 08:19:57 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5474</guid>
		<description>The bug has NOT been fixed..Try checking the same URL with the out param modified

http://docs.google.com/data/contacts?out=xml&#38;show=ALL&#38;psort=Affinity&#38;callback=google&#38;max=99999

now your address book comes out in a xml format..</description>
		<content:encoded><![CDATA[<p>The bug has NOT been fixed..Try checking the same URL with the out param modified</p>
<p><a href="http://docs.google.com/data/contacts?out=xml&amp;show=ALL&amp;psort=Affinity&amp;callback=google&amp;max=99999" rel="nofollow" target="_blank"></a><a href='http://docs.google.com/data/contacts?out=xml&amp;show=ALL&amp;psort=Affinity&amp;callback=google&amp;max=99999' target="_blank">docs.googl...;max=99999</a></p>
<p>now your address book comes out in a xml format..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jake</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5470</link>
		<dc:creator>Jake</dc:creator>
		<pubDate>Tue, 02 Jan 2007 06:11:55 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5470</guid>
		<description>I'm not clear on how we know the bug is fixed.  Couldn't they have just blocked calls from the specific websites that were running the demo exploit?  Is there independent verification?</description>
		<content:encoded><![CDATA[<p>I&#8217;m not clear on how we know the bug is fixed.  Couldn&#8217;t they have just blocked calls from the specific websites that were running the demo exploit?  Is there independent verification?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: YesThatTom</title>
		<link>http://www.cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5467</link>
		<dc:creator>YesThatTom</dc:creator>
		<pubDate>Tue, 02 Jan 2007 05:11:32 +0000</pubDate>
		<guid isPermaLink="false">http://cyber-knowledge.net/blog/2007/01/02/gmails-flaw-is-now-fixed/#comment-5467</guid>
		<description>Imagine if this was an Outlook bug.  It would have taken months (years?) for everyone to upgrade to the latest patch.</description>
		<content:encoded><![CDATA[<p>Imagine if this was an Outlook bug.  It would have taken months (years?) for everyone to upgrade to the latest patch.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
