CyberKnowledge Technology Blog

Everything tech – reviews, tips, software, news

All tech all the time

Welcome to CyberKnowledge technology blog.

Archive for January, 2007

GMail’s Flaw Is Now Fixed

Posted by Alex Bailey On January - 2 - 2007

Earlier I reported that Google had a flaw in which it stores contact details in a JavaScript file on their server. A website could in return declare the function “google”, and put all your contacts and their details into an array. From there it could have been parsed and sent to the malicious server using Ajax. Earlier today there were reports on zdnet that said the flaw was fixed, however at the time it wasn’t true. Currently as of 8 PM EST the flaw has been fixed. When... (more...)

GMail Vulnerable To Contact List Hijacking

Posted by Alex Bailey On January - 1 - 2007

Using a form of cross scripting, it becomes easy to steal a GMail user’s contact list if they visit a certain type of website. The only condition is you have to be logged in to GMail at the time of the attack. GMail is setup to store your contact list in javascript files, which is the core problem. If you log into your GMail account, and click here, you’ll see your contact’s details, along with their email. I’ve tried the hack on IE7, Opera, and Firefox; it appears to... (more...)