AllDeaf.com
Mobile - Perks - Store - Advertise - Spy  

Go Back   AllDeaf.com > Deaf Community > Current Events
LIKE AllDeaf on Facebook FOLLOW AllDeaf on Twitter
  
Reply
LinkBack Thread Tools Display Modes
Unread 01-14-2005, 03:44 PM   #1 (permalink)
Registered User
 
Join Date: Apr 2004
Posts: 4,280
Froogle/Gmail Hack Warning

An Israeli hacker has uncovered a flaw in Froogle, Google's price-comparison service, which could allow access to users' Gmail accounts. Nir Goldshlager, who discovered the flaw, warned that URL-embedded Javascript could end up causing personal information to be revealed.

If users execute the script by clicking a link, they would be redireted to a malicious website. From there, hackers can read a user's cookie. It may contain personal information, such as purchase histories, or the username and password used to access Google services - such as Gmail.
Goldshlager warned that even if the user chooses not to save the cookie, the hacker can still discover the username and password for other services such as Google Alerts and Groups because of the way that data is stored.

Source: http://www.neowin.net/
Vance is offline   Reply With Quote
Alt Today
Deafness

Beitrag Sponsored Links

__________________
This advertising will not be shown in this way to registered members.
Register your free account today and become a member on AllDeaf.com
   
Unread 01-14-2005, 03:51 PM   #2 (permalink)
Deaf258
Guest
 
Posts: n/a
I wonder if Google is aware of this?
  Reply With Quote
Unread 01-14-2005, 04:06 PM   #3 (permalink)
Registered User
 
Join Date: Apr 2004
Posts: 4,280
With Neowin, I am sure google already know about this.
Vance is offline   Reply With Quote
Unread 01-14-2005, 04:13 PM   #4 (permalink)
Registered User
 
Oceanbreeze's Avatar
 
Join Date: Mar 2004
Location: S. FL
Posts: 9,967
Send a message via AIM to Oceanbreeze Send a message via MSN to Oceanbreeze
Quote:
Originally Posted by Magatsu
An Israeli hacker has uncovered a flaw in Froogle, Google's price-comparison service, which could allow access to users' Gmail accounts. Nir Goldshlager, who discovered the flaw, warned that URL-embedded Javascript could end up causing personal information to be revealed.

If users execute the script by clicking a link, they would be redireted to a malicious website. From there, hackers can read a user's cookie. It may contain personal information, such as purchase histories, or the username and password used to access Google services - such as Gmail.
Goldshlager warned that even if the user chooses not to save the cookie, the hacker can still discover the username and password for other services such as Google Alerts and Groups because of the way that data is stored.

Source: http://www.neowin.net/
Thanks for the warning. I contemplated getting a google account, but I guess I won't now.
__________________
"There comes a time in your life, when you walk away from all the drama and people who create it. You surround yourself with people who make you laugh. Forget the bad, and focus on the good. Love the people who treat you right, pray for the ones who don't. Life is too short to be anything but happy. Falling down is a part of life, getting back up is living."
Oceanbreeze is offline   Reply With Quote
Unread 01-15-2005, 12:25 AM   #5 (permalink)
Deaf258
Guest
 
Posts: n/a
Quote:
Originally Posted by Oceanbreeze
Thanks for the warning. I contemplated getting a google account, but I guess I won't now.

It's your loss. Hotmail had so many holes, more so than Google's Gmail.
  Reply With Quote
Unread 01-15-2005, 01:54 PM   #6 (permalink)
Registered User
 
Oceanbreeze's Avatar
 
Join Date: Mar 2004
Location: S. FL
Posts: 9,967
Send a message via AIM to Oceanbreeze Send a message via MSN to Oceanbreeze
Quote:
Originally Posted by Deaf258
It's your loss. Hotmail had so many holes, more so than Google's Gmail.
I don't use my hotmail, either. That's a junk email account that I put on here for safety reasons. Only a select few know what my main email address is.

But, to the point. Google is new, so it doesn't surprise me that it's easily hacked into or might have other problems. I'd prefer to wait until it's been around awhile before I try it. Besides which, I'm happy with what I am using.

Whatever.
__________________
"There comes a time in your life, when you walk away from all the drama and people who create it. You surround yourself with people who make you laugh. Forget the bad, and focus on the good. Love the people who treat you right, pray for the ones who don't. Life is too short to be anything but happy. Falling down is a part of life, getting back up is living."

Last edited by Oceanbreeze; 01-15-2005 at 01:57 PM.
Oceanbreeze is offline   Reply With Quote
Unread 01-15-2005, 02:45 PM   #7 (permalink)
Deaf258
Guest
 
Posts: n/a
Quote:
Originally Posted by Oceanbreeze


I don't use my hotmail, either. That's a junk email account that I put on here for safety reasons. Only a select few know what my main email address is.

But, to the point. Google is new, so it doesn't surprise me that it's easily hacked into or might have other problems. I'd prefer to wait until it's been around awhile before I try it. Besides which, I'm happy with what I am using.

Whatever.
No webmail is safe. I am happier with Gmail than having both Yahoo and Hotmail.
  Reply With Quote
Unread 01-15-2005, 02:50 PM   #8 (permalink)
Registered User
 
Oceanbreeze's Avatar
 
Join Date: Mar 2004
Location: S. FL
Posts: 9,967
Send a message via AIM to Oceanbreeze Send a message via MSN to Oceanbreeze
To each his own.
__________________
"There comes a time in your life, when you walk away from all the drama and people who create it. You surround yourself with people who make you laugh. Forget the bad, and focus on the good. Love the people who treat you right, pray for the ones who don't. Life is too short to be anything but happy. Falling down is a part of life, getting back up is living."
Oceanbreeze is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 12:30 PM.


Join AllDeaf on Facebook!    Follow us on Twitter!

AllDeaf proudly supports St. Jude Children's Research Hospital

Copyright © 2002-2013, AllDeaf.com. All Rights Reserved.