Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | GMail javascript vulnerability


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

GMail javascript vulnerability
Reply
 
Thread Tools
Old 02-03-2006, 13:13   #1
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
GMail javascript vulnerability

Thought this might be of interest to the GMail users amongst us...

Quote:
Originally Posted by Security Dump
source:http://www.securitydump.com/content142.html

A recently discovered vulnerability in Google Gmail allows automatic javascript execution when using the preview function.

While Google filters javascript sent among Gmail accounts, e-mail from outside accounts such as Yahoo! are not filtered.

Normally Gmail would quote the javascript code, however if one includes a short amount of text in the subject and body of the message, then Gmail instead executes the code.

This vulnerability could be used to gather email addresses or compromise viewers Gmail account.
Screenshot
Gareth is offline   Reply With Quote
Old 02-03-2006, 13:28   #2
looking about
 
bopdude's Avatar
 
Join Date: Jun 2003
Location: Teesside
Age: 43
Posts: 7,553
bopdude has a pair of shiny starsbopdude has a pair of shiny starsbopdude has a pair of shiny stars
bopdude has a pair of shiny starsbopdude has a pair of shiny starsbopdude has a pair of shiny starsbopdude has a pair of shiny starsbopdude has a pair of shiny starsbopdude has a pair of shiny starsbopdude has a pair of shiny starsbopdude has a pair of shiny starsbopdude has a pair of shiny starsbopdude has a pair of shiny starsbopdude has a pair of shiny starsbopdude has a pair of shiny stars
Send a message via MSN to bopdude
Re: GMail javascript vulnerability

Nice heads up mate, not using my gmail account at the mo anyways so no problemo.
__________________

bopdude is offline   Reply With Quote
Old 02-03-2006, 13:30   #3
Eric Cartman Wannabe
 
punky's Avatar
 
Join Date: Jun 2003
Location: Cockney geeza land
Age: 27
Services: c:\> net start punky
Posts: 12,013
punky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver bling
punky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver bling
Re: GMail javascript vulnerability

Cheers for the heads up mate
__________________
"We're not here for a long time, we're here for a good time" - Mike Ness (Social Distortion)
"Reach for the sky, 'cause tomorrow may never come" - Reach For The Sky (Social Distortion)
punky is offline   Reply With Quote
Old 03-03-2006, 14:41   #4
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Re: GMail javascript vulnerability

Panic over... according to SANS, this has now been fixed by Google
Gareth is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 01:33.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)