Googlified blog demonstrates that using a form of cross scripting, it becomes easy to steal a GMail user’s contact list if they visit a certain type of website.
The only condition is you have to be logged in to GMail at the time of the attack.
See the demo yourself. Login to gmail and visit the webpage http://googlified.com.googlepages.com/contactlist.htm .

They successfully grabbed 98 contacts from my gmail contact list, including my secret flickr image upload address and some others. Thank god it was a demo and no emails were saved.
shocking ![]()
[via Cyberknowledge]
Technorati Tags: gmail hack, hacking, email
If you enjoyed this post, make sure you subscribe to my RSS feed!
Related Posts:
Posted on March 7, 2007
[…] login to your GMail account and go to this website Read the story in detail at Tech Reads [Via Freakitude […]