Monday, January 1st 2007
Gmail leaves your account open to spammers
A new flaw has been exposed in Google's Gmail service which could allow hackers to get hold of your contacts. When you log into your Gmail (Googlemail in some countries) account, Google will put your details into a JavaScript file. Because of this, if you browse other websites whilst logged into your account, any of them could potentially declare the function "google" and be able to get hold of all of your contacts. The only two ways to ensure your privacy is safe are to disable JavaScript in all websites except those you trust or to not browse other sites whilst logged into any Google service. Admittedly Gmail is still only a beta, but a fault like this could be quite serious.
Update: Disabling JavaScript did not solve this problem, however it appears that Google has now fixed this issue and your contacts list should be safe.
Source:
Engadget
Update: Disabling JavaScript did not solve this problem, however it appears that Google has now fixed this issue and your contacts list should be safe.
16 Comments on Gmail leaves your account open to spammers
Turn on Java to read your mails?
Lol, how far have we gone... :D
And here another usefull thing:
www.customizegoogle.com/
No more annoying ads! :D
(i don't have java installed)
Edit: Gah to having to escape characters within code tags ...
Edit: well I disabled JavaScript and that page still shows my contacts... but Gmail doesn't work. Probably need to clear my cookies ect.
Edit2: Disabling JavaScript does NOT seem to solve this problem, that link still shows my contacts after I have cleared all my internet data with Javascript disabled... and I can't even use the Gmail service!!!
Edit3: Couldn't the line
script language="javascript" xsrc="http://video.google.com/data/contacts?out=js&max=500 &psort=Affinity&callback=getContacts"
be linked to this?
google ({
Success: false,
Errors: []
})
Using FireFox.
When I clicked that link earlier it would bring up a list in which you could find any info about your contacts you had saved.