Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

January 2nd, 2007, 09:42 GMT · By Bogdan Popa

Gmail Hacked! Your Contact List Can Be Stolen!

SHARE:

Adjust text size:


Gmail is the mail service provided by Google and it was one of the first mail solutions that offered its users a 1 GB account, allowing you to save all kinds of stuff. Even if the service was released a long time ago, it is available only by invitation and provides you with several functions to control your mail account.

In the previous months, security companies and multiple users reported some important vulnerabilities in Google services that can allow an attacker to view private information
or even control your computer. This time it's Gmail's turn with a security flaw that can help malicious persons steal your contact list.

"Haochi Chen discovered what looks like a Gmail XSS (cross-site scripting) security problem. Using a small piece of JavaScript you can put on any server, the user's contact names & email addresses are revealed (provided you're logged in to your Google account). I was able to reproduce this using Firefox, and an updated version of the original snippet. With Haochi's code, a malicious website would be able to grab your contact list and transmit it to their server behind the scenes, storing this data for other purposes - like spamming, or finding out more about you," Philipp Lenssen said on a blog post on his blog.

Imagine that after your contact list is exported from your account, an attacker can use it to exploit a lot of other vulnerabilities, using spam methods or other malicious ways available via the mail service.
Google already patched the issue but only after about 30 hours since the company was informed about the vulnerability. No matter its severity rating, it's obvious that Google is continuously affected by security flaws so we should expect for a Google response soon.

TELL US WHAT YOU THINK:

4,955 hits · 4 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Ballmer: Google might dissapear in the next five years!

One More Google Vulnerability!

New Service to Track Google Bugs

How to Contact Google

Google: "Google Search Appliance Is Safe!"

READER COMMENTS:


Comment #1 by: wwwluckyro on 02 Jan 2007, 12:01 UTC reply to this comment

your title pretty much sucks.... it's just to get atention..

Comment #1.1 by: Max on 29 May 2008, 02:42 GMT

Unfortunately for many people this title is correct. I found many people with this issue and it's still happening even if in theory was fixed.


Comment #2 by: Nisha on 10 Jun 2008, 11:05 UTC reply to this comment

I agree with Max. The title is very true. I had my contact list stolen just yesterday!!


Comment #3 by: Brent on 18 Nov 2008, 03:08 UTC reply to this comment

Had mine stolen last night. A friend sent me and SMS this morning telling me I might have a problem. He was right !!

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM