Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy problems
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 21st, 2010, 12:23 AM
vasa1's Avatar
vasa1 vasa1 is offline
Massive Poster
 
Join Date: May 2010
Posts: 3,988
Default A site that grabs your GMail address

Whoa, Google, That’s A Pretty Big Security Hole

Quote:
If you’re already logged in to any Google account (Gmail, etc.), and visit that site, he’s harvested your Google email. And proves it by emailing you immediately. ...

And it even works in “incognito” mode (also known as porn mode).

In edit: that site is now down! and the problem fixed (for now).

Quote:
Google says the issue is now resolved: “We quickly fixed the issue in the Google Apps Script API that could have allowed for emails to be sent to Gmail users without their permission if they visited a specially designed website while signed into their account. We immediately removed the site that demonstrated this issue, and disabled the functionality soon after. We encourage responsible disclosure of potential application security issues to security@google.com.”
  #2  
Old November 21st, 2010, 06:44 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: A site that grabs your GMail address

Good that was fixed quick. What other are left I wonder.
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #3  
Old November 21st, 2010, 09:19 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,439
Default Re: A site that grabs your GMail address

Maybe this sounds like a stupid question, but it was not mentioned whether or not you had to be signed in within the same browser session? Would it be possible for it to happen, even if having Gmail open in a different session (same or different web browser)?
  #4  
Old November 21st, 2010, 09:30 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: A site that grabs your GMail address

maybe more will be revealed later and the moment it seems a bug was in google api (maybe not checking access correctly). that blog site itself is part of google
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #5  
Old November 21st, 2010, 09:38 AM
culla's Avatar
culla culla is offline
Frequent Poster
 
Join Date: Aug 2005
Posts: 492
Default Re: A site that grabs your GMail address

t happens in hotmail too
  #6  
Old November 21st, 2010, 09:39 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: A site that grabs your GMail address

Quote:
Originally Posted by culla
t happens in hotmail too
what does
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #7  
Old November 21st, 2010, 10:19 AM
SweX SweX is offline
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,612
Default Re: A site that grabs your GMail address

Scary stuff indeed .

But I do always log-out when ever I am done with my email account or any other account for that matter to be sure something like this won't happen.
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-
 

Wilders Security Forums > Privacy Related Topics > privacy problems « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:40 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums