<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; hacking-gmail</title>
	<atom:link href="http://www.darknet.org.uk/tag/hacking-gmail/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Hackers Get Hold Of Wildcard Google SSL Certificate &#8211; Could Hijack Gmail Accounts</title>
		<link>http://www.darknet.org.uk/2011/08/hackers-get-hold-of-wildcard-google-ssl-certificate-could-hijack-gmail-accounts/</link>
		<comments>http://www.darknet.org.uk/2011/08/hackers-get-hold-of-wildcard-google-ssl-certificate-could-hijack-gmail-accounts/#comments</comments>
		<pubDate>Tue, 30 Aug 2011 16:48:05 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[DigiNotar]]></category>
		<category><![CDATA[gmail mitm]]></category>
		<category><![CDATA[gmail security]]></category>
		<category><![CDATA[gmail-hacking]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[google mitm]]></category>
		<category><![CDATA[google ssl cert]]></category>
		<category><![CDATA[google wildcard cert]]></category>
		<category><![CDATA[hacking-gmail]]></category>
		<category><![CDATA[how to hack gmail]]></category>
		<category><![CDATA[man-in-the-middle]]></category>
		<category><![CDATA[mitm]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3181</guid>
		<description><![CDATA[One of the big discussions points this week is about a wildcard cert for Google that has leaked out from a Dutch company called DigiNotar. The certificate is good for all Google domains &#8211; it&#8217;s a *.google.com cert. This is bad news and apparently has been in the wild for a while, some people are [...]]]></description>
			<content:encoded><![CDATA[<p>One of the big discussions points this week is about a wildcard cert for <a href="http://www.darknet.org.uk/tag/google/">Google</a> that has leaked out from a Dutch company called DigiNotar. The certificate is good for all Google domains &#8211; it&#8217;s a *.google.com cert.</p>
<p>This is bad news and apparently has been in the wild for a while, some people are linking to deaths in Iran as the cert could be used to hijack Gmail accounts using a <a href="http://www.darknet.org.uk/tag/mitm/">MITM</a> attack.</p>
<p>If you want to check out the cert directly, you can do so here:</p>
<p><a href="http://pastebin.com/ff7Yg663">Gmail.com SSL MITM ATTACK BY Iranian Government &#8211; 27/8/2011</a></p>
<p>The story seems to originate here where a user in Iran noticed a MITM was being perpetrated on him &#8211; probably by his own ISP or government.</p>
<p><a href="http://www.google.co.uk/support/forum/p/gmail/thread?tid=2da6158b094b225a&#038;hl=en">Is This MITM Attack to Gmail&#8217;s SSL ?</a> </p>
<blockquote><p>Hackers have obtained a digital certificate good for any Google website from a Dutch certificate provider, a security researcher said today. Criminals could use the certificate to conduct &#8220;man-in-the-middle&#8221; attacks targeting users of Gmail, Google&#8217;s search engine or any other service operated by the Mountain View, Calif. company.</p>
<p>&#8220;This is a wildcard for any of the Google domains,&#8221; said Roel Schouwenberg, senior malware researcher with Kaspersky Lab, in an email interview Monday.</p>
<p>&#8220;[Attackers] could poison DNS, present their site with the fake cert and bingo, they have the user&#8217;s credentials,&#8221; said Andrew Storms, director of security operations at nCircle Security.</p>
<p>Man-in-the-middle attacks could also be launched via spam messages with links leading to a site posing as, say, the real Gmail. If recipients surfed to that link, their account login username and password could be hijacked. Details of the certificate were posted on Pastebin.com last Saturday. Pastebin.com is a public site where developers &#8212; including hackers &#8212; often post source code samples.</p>
<p>According to Schouwenberg, the SSL (secure socket layer) certificate is valid, and was issued by DigiNotar, a Dutch certificate authority, or CA. DigiNotar was acquired earlier this year by Chicago-based Vasco, which bills itself on its site as &#8220;a world leader in strong authentication.&#8221;</p>
<p>Vasco did not reply to a request for comment.</p></blockquote>
<p>The cert is valid, which is scary. One thing which is currently unknown is how the cert got out there, if it was a hack or a leak or someone from the outside got access to the DigiNotar CA.</p>
<p>If you want more technical details on how to verify the cert, you can check this out:</p>
<p><a href="http://pastebin.com/SwCZqskV">Internet death sentence for DigiNotar&#8217;s Root CA!</a></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Security researcher and Tor developer Jacob Applebaum confirmed that the certificate was valid in an email answer to Computerworld questions, as did noted SSL researcher Moxie Marlinspike on Twitter. &#8220;Yep, just verified the signature, that pastebin *.google.com certificate is real,&#8221; said Marlinspike .</p>
<p>Because the certificate is valid, a browser would not display a warning message if its user went to a website signed with the certificate.</p>
<p>It&#8217;s unclear whether the certificate was obtained because of a lack of oversight by DigiNotar or through a breach of the company&#8217;s certificate issuing website.</p>
<p>Schouwenberg urged the company to provide more information as soon as possible.</p>
<p>&#8220;Given their ties to the government and financial sectors it&#8217;s extremely important we find out the scope of the breach as quickly as possible,&#8221; Schouwenberg said. The situation was reminiscent of a breach last March, when a hacker obtained certificates for some of the Web&#8217;s biggest sites, including Google and Gmail, Microsoft, Skype and Yahoo.</p>
<p>Then, Comodo said that nine certificates had been fraudulently issued after attackers used an account assigned to a company partner in southern Europe.</p>
<p>Initially, Comodo argued that Iran&#8217;s government may have been involved in the theft. Days later, however, a solo Iranian hacker claimed responsibility for stealing the SSL certificates.</p>
<p>Today, Kaspersky&#8217;s Schouwenberg said &#8220;nation-state involvement is the most plausible explanation&#8221; for the acquisition of the DigiNotar-issued certificate. </p></blockquote>
<p>Google have also mentioned in on their security blog here:</p>
<blockquote><p>Today we received reports of attempted SSL man-in-the-middle (MITM) attacks against Google users, whereby someone tried to get between them and encrypted Google services. The people affected were primarily located in Iran. The attacker used a fraudulent SSL certificate issued by DigiNotar, a root certificate authority that should not issue certificates for Google (and has since revoked it).</p></blockquote>
<p><a href="http://googleonlinesecurity.blogspot.com/2011/08/update-on-attempted-man-in-middle.html">An update on attempted man-in-the-middle attacks</a></p>
<p>There was also quick action taken by both <a href="http://blog.mozilla.com/security/2011/08/29/fraudulent-google-com-certificate/">Mozilla</a> and <a href="http://blogs.technet.com/b/msrc/archive/2011/08/29/microsoft-releases-security-advisory-2607712.aspx">Microsoft</a>.</p>
<p>It&#8217;s been pretty quiet really to say this is really a major issue, I hope more details come out about how this occurred. If you are using Firefox there are instructions on how to delete/distrust the DigiNotar CA <a href="http://support.mozilla.com/en-US/kb/deleting-diginotar-ca-cert">here</a>.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/082911-hackers-acquire-google-certificate-could-250220.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Hackers+Get+Hold+Of+Wildcard+Google+SSL+Certificate+%E2%80%93+Could+Hijack+Gmail+Accounts+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3181+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/08/hackers-get-hold-of-wildcard-google-ssl-certificate-could-hijack-gmail-accounts/&amp;t=Hackers+Get+Hold+Of+Wildcard+Google+SSL+Certificate+%E2%80%93+Could+Hijack+Gmail+Accounts" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/08/hackers-get-hold-of-wildcard-google-ssl-certificate-could-hijack-gmail-accounts/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/08/hackers-get-hold-of-wildcard-google-ssl-certificate-could-hijack-gmail-accounts/&amp;title=Hackers+Get+Hold+Of+Wildcard+Google+SSL+Certificate+%E2%80%93+Could+Hijack+Gmail+Accounts" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/08/hackers-get-hold-of-wildcard-google-ssl-certificate-could-hijack-gmail-accounts/&amp;title=Hackers+Get+Hold+Of+Wildcard+Google+SSL+Certificate+%E2%80%93+Could+Hijack+Gmail+Accounts" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/08/hackers-get-hold-of-wildcard-google-ssl-certificate-could-hijack-gmail-accounts/&amp;title=Hackers+Get+Hold+Of+Wildcard+Google+SSL+Certificate+%E2%80%93+Could+Hijack+Gmail+Accounts" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/08/hackers-get-hold-of-wildcard-google-ssl-certificate-could-hijack-gmail-accounts/&amp;title=Hackers+Get+Hold+Of+Wildcard+Google+SSL+Certificate+%E2%80%93+Could+Hijack+Gmail+Accounts" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F08%2Fhackers-get-hold-of-wildcard-google-ssl-certificate-could-hijack-gmail-accounts%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/08/hackers-get-hold-of-wildcard-google-ssl-certificate-could-hijack-gmail-accounts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Retarded E-mails &#8211; Carding, Coins, Bombs &amp; More!</title>
		<link>http://www.darknet.org.uk/2009/10/retarded-e-mails-carding-coins-bombs-more/</link>
		<comments>http://www.darknet.org.uk/2009/10/retarded-e-mails-carding-coins-bombs-more/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 08:35:30 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Retards]]></category>
		<category><![CDATA[brute-force]]></category>
		<category><![CDATA[carding]]></category>
		<category><![CDATA[cracking]]></category>
		<category><![CDATA[credit card numbers]]></category>
		<category><![CDATA[hack facebook]]></category>
		<category><![CDATA[hack hotmail]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking yahoo]]></category>
		<category><![CDATA[hacking yahoo mail]]></category>
		<category><![CDATA[hacking-gmail]]></category>
		<category><![CDATA[idiots]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2210</guid>
		<description><![CDATA[Ah it&#8217;s that time of the year again when all the back to skoolers have some mad l33t knowledge and wanna h4x0r the planet or something. Hmmm website hacking, sounds simple eh? thriller wrote: hai i would like to know website hacking how?&#8230;&#8230;&#8230; sedn to my mail Ok I&#8217;m following up up to the exploding [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah it&#8217;s that time of the year again when all the back to skoolers have some mad l33t knowledge and wanna h4x0r the planet or something.</p>
<p>Hmmm website hacking, sounds simple eh?</p>
<blockquote><p>thriller wrote:<br />
hai i would like to know website hacking how?&#8230;&#8230;&#8230; sedn to my mail</p></blockquote>
<p>Ok I&#8217;m following up up to the exploding part? Not quite sure about that one.</p>
<blockquote><p>kesarjahs wrote:<br />
hi 2 all, i just want to ask if you have program for hacking of yahoomail /gmail account? If you don&#8217;t mind can you send it to my gmail account coz i want to hack and try to explode. I&#8217;m looking forward to the end such a long time.</p>
<p>sincerely,<br />
            Kesar Jahs</p></blockquote>
<p>Ok this one is really bizarre, what kind of question does he expect actually?</p>
<blockquote><p>Jason Davis wrote:<br />
What is this site. I&#8217;m a lil lost<br />
J</p></blockquote>
<p>WTF, does this look like Security Focus? Oh right copy and paste, at least have the decency to change the e-mail you lazy fuck.</p>
<blockquote><p>Rudra wrote:<br />
Hello,<br />
I&#8217;m the senior product manager and a founder employee of Wank Security &#8211; the industry&#8217;s leading on demand penetration testing company. Previously I&#8217;ve written articles in Hakin9, infosec magazine and CISSP training materials for renowned authors. I would also like to contribute to Security focus on a wide variety of topics including penetration testing. Please let me know if you are accepting articles at this point. Offline, I&#8217;ve been working on a article on security threats for online gaming. I can contribute this one if it fits your requirement to start with.</p>
<p>Hope to hear from you soon!</p>
<p>Thanks!<br />
Rudra</p></blockquote>
<p>Ah back to the normal cheating spouse/erase my debt thing going on.</p>
<blockquote><p>Aliana wrote:<br />
Quick background &#8211; I would like to start a new life, my x husband ran my credit to the ground. I am a 28 year old mother and am seeking someone who can help me erase my debt. If you know of anyone please pass on my email address, if not I am sorry to have wasted your time.  Thank you!</p></blockquote>
<p>What&#8217;s the bet this guy is Indian, all their e-mails start with &#8216;Sir&#8217;. BTW if you find the magic undetectable hacking tool Fadi, I want a copy too &#8211; thanks.</p>
<blockquote><p>Fadi wrote:<br />
Dear Sir,<br />
        i m looking for undetectable hacking tool to purchase is there any so please tell mei didn&#8217;t found any yet :( please sir i shall be highly thankfull to u .</p></blockquote>
<p>I&#8217;m not exactly sure what kind of site people think this is, but since when did we do identity searches? She didn&#8217;t even mention what country she&#8217;s in or how I&#8217;m supposed to locate this mysterious person.</p>
<blockquote><p>Nia wrote:<br />
Do u need the permission of the individual to be able to give me their location?<br />
And how much will it cost for one search?</p>
<p>Website: Hotmail</p></blockquote>
<p>Credit cards? I have plenty, you can have them all if you want..I keep buying stuff I don&#8217;t really need.</p>
<blockquote><p>noname wrote:<br />
I want to buy credit card what to do to buy?</p></blockquote>
<p>mig22 or mig33? Make up your mind..</p>
<blockquote><p>ahmad wrote:<br />
dear friend,<br />
   i just wanted  to request you something. there is a software used for chating via mobile. its name is mig22. i want to request you to find some way or make some software for that , for hacking or cracking mig33 password. i will be very thankful to you.<br />
  waiting for your reply</p></blockquote>
<p>Oh wow, poor you Louis. I swear people seem to think every &#8216;hacker&#8217; runs some kind of hack on demand password recovery scheme.</p>
<blockquote><p>Louis wrote:<br />
Hi,</p>
<p>My ex stole my email accounts and changed all the details so I cant access them or recover them, can you please help me get the passwords so I can recover the email accounts?</p>
<p>Thanks in advance,</p>
<p>Louis</p></blockquote>
<p>This one sounds like a 419er.</p>
<blockquote><p>collins masango wrote:<br />
i would need a good creditcard dealer to be suppling me with numbers,this for long time deal,preferably russian,german,canadian,uk or american</p></blockquote>
<p>This one is a little bit scary..and disjointed, coins and bombs? What a combination.</p>
<blockquote><p>Alana wrote:<br />
I looking for imfo on atm and coin machines and how to crack into them and on bombs</p></blockquote>
<p>Keep an eye on the retards here:</p>
<p></p>
<p><a href="http://www.darknet.org.uk/category/retards/">http://www.darknet.org.uk/category/retards/</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Retarded+E-mails+%E2%80%93+Carding%2C+Coins%2C+Bombs+%26+More%21+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2210+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/retarded-e-mails-carding-coins-bombs-more/&amp;t=Retarded+E-mails+%E2%80%93+Carding%2C+Coins%2C+Bombs+%26+More%21" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/10/retarded-e-mails-carding-coins-bombs-more/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/retarded-e-mails-carding-coins-bombs-more/&amp;title=Retarded+E-mails+%E2%80%93+Carding%2C+Coins%2C+Bombs+%26+More%21" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/retarded-e-mails-carding-coins-bombs-more/&amp;title=Retarded+E-mails+%E2%80%93+Carding%2C+Coins%2C+Bombs+%26+More%21" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/10/retarded-e-mails-carding-coins-bombs-more/&amp;title=Retarded+E-mails+%E2%80%93+Carding%2C+Coins%2C+Bombs+%26+More%21" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/retarded-e-mails-carding-coins-bombs-more/&amp;title=Retarded+E-mails+%E2%80%93+Carding%2C+Coins%2C+Bombs+%26+More%21" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F10%2Fretarded-e-mails-carding-coins-bombs-more%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/retarded-e-mails-carding-coins-bombs-more/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Google Fixes Serious Vulnerability in Gmail</title>
		<link>http://www.darknet.org.uk/2007/02/google-fixes-serious-vulnerability-in-gmail/</link>
		<comments>http://www.darknet.org.uk/2007/02/google-fixes-serious-vulnerability-in-gmail/#comments</comments>
		<pubDate>Fri, 09 Feb 2007 08:27:18 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[email-hacking]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[gmail-exploit]]></category>
		<category><![CDATA[gmail-hacking]]></category>
		<category><![CDATA[google-hacking]]></category>
		<category><![CDATA[hacking-email]]></category>
		<category><![CDATA[hacking-gmail]]></category>
		<category><![CDATA[hacking-google]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/02/google-fixes-serious-vulnerability-in-gmail/</guid>
		<description><![CDATA[Google started the new year by fixing a serious vulnerability in Gmail. This was quite an interesting case and once again (as everything relating to web apps seems to be nowdays) it was an XSS flaw that allowed malicious attackers to steal your contact list, leading to some pretty bad information leakage. Google has fixed [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Google started the new year by fixing a serious vulnerability in Gmail.</p>
<p>This was quite an interesting case and once again (as everything relating to web apps seems to be nowdays) it was an XSS flaw that allowed malicious attackers to steal your contact list, leading to some pretty bad information leakage.</p>
<blockquote><p>Google has fixed a vulnerability in its popular GMail web mail service that creates a means for hackers to steal users&#8217; contact lists.</p>
<p>The cross-site scripting flaw stemmed from the decision by GMail to store contact lists in a JavaScript file. GMail always saves contact lists as JavaScript code using the same URL, so a script featuring this URL can read out the fields of a users&#8217; contact list. GMail failed to check what sites were attempting to run this &#8220;callback&#8221; function.</p></blockquote>
<p>There was a previous very similar flaw on Google which effected computers with multiple Gmail users.</p>
<blockquote><p>As a result users logged into GMail, or other Google services sharing the same login, are liable to hand over their contact list to spammers or other miscreants providing they are tricked into visiting a maliciously constructed website. Exploitation would have been as simple as fooling users into visiting a hostile website through spam messages sent to users&#8217; email accounts.</p>
<p>Coders failed to take into account that it was a bad idea to save sensitive data as JavaScript, under predictable URLs, a problem Google watchers spotted shortly after Google made the coding changes last week</p></blockquote>
<p>I do like Google though, they tend to fix things pretty fast!</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2007/01/02/gmail_exploit/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Google+Fixes+Serious+Vulnerability+in+Gmail+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D445+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/02/google-fixes-serious-vulnerability-in-gmail/&amp;t=Google+Fixes+Serious+Vulnerability+in+Gmail" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/02/google-fixes-serious-vulnerability-in-gmail/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/02/google-fixes-serious-vulnerability-in-gmail/&amp;title=Google+Fixes+Serious+Vulnerability+in+Gmail" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/02/google-fixes-serious-vulnerability-in-gmail/&amp;title=Google+Fixes+Serious+Vulnerability+in+Gmail" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/02/google-fixes-serious-vulnerability-in-gmail/&amp;title=Google+Fixes+Serious+Vulnerability+in+Gmail" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/02/google-fixes-serious-vulnerability-in-gmail/&amp;title=Google+Fixes+Serious+Vulnerability+in+Gmail" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F02%2Fgoogle-fixes-serious-vulnerability-in-gmail%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/02/google-fixes-serious-vulnerability-in-gmail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

