
Earlier I reported that Google had a flaw in which it stores contact details in a JavaScript file on their server. A website could in return declare the function “google”, and put all your contacts and their details into an array. From there it could have been parsed and sent to the malicious server using Ajax. Earlier today there were reports on zdnet that said the flaw was fixed, however at the time it wasn’t true. Currently as of 8 PM EST the flaw has been fixed. When... (more...)



