Google Blogoscoped

Forum

Gmail Bug: Your Gmail Contact List is Being Expose to Spammers

Haochi [PersonRank 10]

Monday, January 1, 2007
17 years ago5,223 views

A recent discovered bug (by me) in Gmail can expose your email address and your contact list to spammers.

I have notified the Google Security team this morning and the bug hasn't yet been fixed, looks like it needs some attentions before Google will look deeper into it.

example: http://googlified.com.googlepages.com/contactlist.htm

digg it here: http://digg.com/security/Gmail_Bug_Your_Gmail_Contact_List_is_Being_Expose_to_Spammers

Brinke Guthrie [PersonRank 10]

17 years ago #

what is this?

Hong Xiaowan [PersonRank 10]

17 years ago #

How to do?

Eytan Buchman [PersonRank 10]

17 years ago #

Great find. Wonder how long it is before this gets fixed. I think I will log out of my Google Account until then.

Philipp Lenssen [PersonRank 10]

17 years ago #

Doesn't seem to work here? I see no contact list on your page?

Jake's View [PersonRank 10]

17 years ago #

I can't see it either.

Wouter Schut [PersonRank 10]

17 years ago #

This indeed works. But you should have given google more time to fix it. You're trading karma for hits here.

Hong Xiaowan [PersonRank 10]

17 years ago #

It seams AJAX bug for pass one website to another. Give different user a different encryption for cookies only access at the user's own position can settle this.
But will make the user feel diffcult when travel from here to their.

Google tech based on the classic internet procotol, the bugs from the old protocol. I think google have no way to settle them.

I also find a bug at google groups. At last, I know that is not google's reason. It is Smtp's bug. Nobody can fix it. Or fix all.

stefan2904 [PersonRank 10]

17 years ago #

http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/
by http://digg.com/programming/GMail_Hacked_Visit_ANY_Website_and_Your_Whole_Contact_List_Can_be_Stolen

stefan2904 [PersonRank 10]

17 years ago #

oh shit, this link works!
(http://docs.google.com/data/contacts?out=js&show=ALL&psort=Affinity&callback=google&max=99999)

Eytan Buchman [PersonRank 10]

17 years ago #

Now you've made the Diggers angry. Uh oh.

TOMHTML [PersonRank 10]

17 years ago #

It's really a MAJOR issue found by Haochi. Poor googlers who have to fix it since the first hour of the year... ;-)

Haochi [PersonRank 10]

17 years ago #

Haha, the Digg comments are really funny. :)

Juha-Matti Laurio [PersonRank 10]

17 years ago #

There is a new report saying Google Security Team has fixed it already:
"Serious Gmail vulnerability fixed"
http://blogs.zdnet.com/Google/?p=434

Ionut Alex. Chitu [PersonRank 10]

17 years ago #

That is old.

Philipp Lenssen [PersonRank 10]

17 years ago #

Haochi, as you probably know by now, you got to give the Google security team more time than a couple of hours to get back to you (unless posting about the vulnerability doesn't help abusers, but only helps users). I guess something like a week or more is more realistic...

Juha-Matti Laurio [PersonRank 10]

17 years ago #

31st Dec but not listed in this thread earlier.

Juha-Matti Laurio [PersonRank 10]

17 years ago #

My post including the release date of ZDNet Blog entry is a reply to Ionut Alex. Chitu...

Forum home

Advertisement

 
Blog  |  Forum     more >> Archive | Feed | Google's blogs | About
Advertisement

 

This site unofficially covers Google™ and more with some rights reserved. Join our forum!