ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Become a ZDNet.co.uk member

Tom Espiner

View blog's RSS Feed

Security Bullet In

Communiques from the security front, sir

Tuesday 2 January 2007, 3:46 PM

Gmail flaw fixed?

Posted by Tom Espiner

It is still uncertain how serious a javascript flaw in Gmail is, and whether it has been fixed completely. The flaw allows spammers to harvest contact details from a user's account by launching a cross-site scripting attack.

To exploit the flaw, the hacker adds a piece of code to their website server, which in turn gives them access to the Gmail contacts of passing browsers, if users are signed in to their Gmail account.

There is some speculation about how serious a flaw this is, and whether there has been a complete fix. According to ZDNet blogger Garrett Rogers Google has partially sorted out the problem.

"The problem is only partially fixed. The vulnerability exposed through video.google.com has been patched up, but there are other subdomains where the problem still exists," said Rogers in his blog.

Google was unavailable for comment at the time of writing.


Comments on this post

Tom Espiner
  • Tom Espiner
  • London, UK
  • Member since: October 2006
ZDNet Staff

Contacts

Number of Contacts: 1

Contacts' Latest Discussions

Number of Tracked Discussions: 411

roger andre roger andre

SP3 Under Suspicion Again

Saturday 19 July 2008, 9:29 PM

2 comments
roger andre roger andre

iPhone heaven/iPhone hell

Saturday 19 July 2008, 8:52 PM

3 comments

Contacts' Latest Blogs

Number of Contacts Blogs: 1