网管联盟 | 网管论坛 | 网管u家 | 网管博客 | 网管软件 | 网管求职 | 小游戏 | 网管搜索 | 网管原创 | 网管聚合 | 网管读摘 | 网管焦点 | 世界素材 | 会员投稿 | 会员中心 
中国网管联盟
Windows Linux Cisco 网络技术 数据库 黑客攻防 DotNet Java PHP 认证 新闻资讯 服务器 存储资讯 网络设备 网管学堂 技术专题 焦点 网吧频道
 当前位置: > bitsCN.com > 网络攻防 > 黑客技术 > Exploit > GMail Vulnerable To Contact List Hijacking  

GMail Vulnerable To Contact List Hijacking

2007-02-01  作者:bitsCN整理  来源:中国网管联盟  点评 投稿 收藏

Using a form of cross scripting, it becomes easy to steal a GMail user抯 contact list if they

visit a certain type of website. The only condition is you have to be logged in to GMail at the

time of the attack. GMail is setup to store your contact list in javascript files, which is the

core problem. If you log into your GMail account, and click here -


http://docs.google.com/data/contacts?out=js&show=ALL&psort=Affinity&callback=google&max=99999

you抣l see your contact抯 details, along with their email. I've tried the hack on IE7, Opera, and

Firefox; it appears to be working on all three. To see a demonstration of the attack, login to

your GMail account and go to this website -
http://googlified.com.googlepages.com/contactlist.htm

I don抰 know for sure if the list is being saved or not, so browse at your own risk. According to

the website they aren抰 saving the data.

Something worth noting is that the email it claims is yours, is never yours. I tried it on two
中国网管论坛bbs.bitsCN.com


different emails, and it failed both times. However both times it listed the address I get email

from most as mine. Also in the image I've included, shows 23 contacts when it did indeed list all

200 or so.



This has been a problem before for GMail, and more details about the previous attacks can be found

here. I guess this is why they keep the service in beta.

more @ source.

TAGs     the   to   is   it   GMail   your   and   in   list   of   you   they   on      
 上一篇:Cookie Stealing Upgrade: Ajax Style   下一篇:simplog0932.txt
GMail Vulnerable To Contact List Hijacking 评论:
loading.. 评论加载中…
评论:请自觉遵守互联网相关政策法规,评论不得超过250字。

验证码: 注册用户
本类热门排行:
最新推荐文章:
网管论坛交流: