The is a vulnerability in GMail contact. By using cross site scripting, it's easy to steal a GMail user’s contact list if you visit a certain type of website. The attack is simple, you have to be logged in to GMail at the time of the attack. Visit this website for more information about this vulnerability:
http://cyber-knowledge.net/blog/2007/01/01/gmail-vulnerable-to-contact-list-hijacking/
Monday, January 01, 2007
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment