<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Gmail contacts flaw: Overview and suggestions</title>
	<atom:link href="http://betterexplained.com/articles/gmail-contacts-flaw-overview-and-suggestions/feed/" rel="self" type="application/rss+xml" />
	<link>http://betterexplained.com/articles/gmail-contacts-flaw-overview-and-suggestions/</link>
	<description>Learning shouldn't hurt. Let's share the insights that made difficult ideas click.</description>
	<lastBuildDate>Sat,  7 Nov 2009 23:27:48 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: The Cross-Site Request Forgery (CSRF/XSRF) FAQ &#171; Dogfeeds——IT Telescope</title>
		<link>http://betterexplained.com/articles/gmail-contacts-flaw-overview-and-suggestions/#comment-247883</link>
		<dc:creator>The Cross-Site Request Forgery (CSRF/XSRF) FAQ &#171; Dogfeeds——IT Telescope</dc:creator>
		<pubDate>Mon, 06 Jul 2009 08:10:55 +0000</pubDate>
		<guid isPermaLink="false">http://betterexplained.com/articles/gmail-contacts-flaw-overview-and-suggestions/#comment-247883</guid>
		<description>[...] A vulnerability in GMail was discovered in January 2007 which allowed a attacker to steal a GMail user&#8217;s contact list. A different issue was discovered in Netflix which allowed an attacker to change the name and address on the account, as well as add movies to the rental queue etc&#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] A vulnerability in GMail was discovered in January 2007 which allowed a attacker to steal a GMail user&#8217;s contact list. A different issue was discovered in Netflix which allowed an attacker to change the name and address on the account, as well as add movies to the rental queue etc&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Google Chrome + SE Linux = Navegador Blindado &#171; Ulisses Castro (thebug) - Ethical Hacking, Pentest and Computer Security</title>
		<link>http://betterexplained.com/articles/gmail-contacts-flaw-overview-and-suggestions/#comment-198839</link>
		<dc:creator>Google Chrome + SE Linux = Navegador Blindado &#171; Ulisses Castro (thebug) - Ethical Hacking, Pentest and Computer Security</dc:creator>
		<pubDate>Thu, 11 Sep 2008 21:58:12 +0000</pubDate>
		<guid isPermaLink="false">http://betterexplained.com/articles/gmail-contacts-flaw-overview-and-suggestions/#comment-198839</guid>
		<description>[...] Com isto já podemos imaginar as possibilidades por exemplo navegar com uma aba nas páginas da intranet da sua empresa tranquilamente e em outra aba você poderia navegar pelos sites mais promíscuos do universo sem ter medo, pois são duas abas completamente isoladas e cada uma trancafiada dentro de seu próprio domínio! Será que CSRF, XSS e similares estão com os dias contados?:) Será que CSRF, similares e ataques como este por exemplo, estão com os dias contados? :( [...]</description>
		<content:encoded><![CDATA[<p>[...] Com isto já podemos imaginar as possibilidades por exemplo navegar com uma aba nas páginas da intranet da sua empresa tranquilamente e em outra aba você poderia navegar pelos sites mais promíscuos do universo sem ter medo, pois são duas abas completamente isoladas e cada uma trancafiada dentro de seu próprio domínio! Será que CSRF, XSS e similares estão com os dias contados?:) Será que CSRF, similares e ataques como este por exemplo, estão com os dias contados? <img src='http://betterexplained.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maria.Germany</title>
		<link>http://betterexplained.com/articles/gmail-contacts-flaw-overview-and-suggestions/#comment-125652</link>
		<dc:creator>Maria.Germany</dc:creator>
		<pubDate>Mon, 21 Jan 2008 15:59:27 +0000</pubDate>
		<guid isPermaLink="false">http://betterexplained.com/articles/gmail-contacts-flaw-overview-and-suggestions/#comment-125652</guid>
		<description>Hello,
I know &quot;nothing&quot; about programming but urgently need help! My contact list and parts of emails are spyed out (storaged in cookies)!!! 

Last Thursday I was logged into my gmail account when suddenly everything slowed down and certain functions like &quot;compose&quot; didn&#039;t work anymore.

I clear out my folder &quot;temporary internet files&quot; once or twice a day. When gmail wasn&#039;t working properly I logged in and out and switched to the folder &quot;temporary internet files&quot;.

I saw that a CONTACT ADDRESS which I didn&#039;t use for about 3 years was  part of the text of a cookie. I cleared the folder but when I logged in again there was the same cookie. 

Same happened with about 20 other contacts, most of them I didn&#039;t use for years!

I then cleared my contact list.

Then it was getting even scarier: Parts of old message and data were part of new created cookies.

There are other cookies which show symbols like ?????????, %%%% or squares. 

The most extreme which happened then was: I did screenshots of the suspicious cookies to have some sort of  documentation. I storaged these screenshots in a completely different folder. Suddenly there was in the folder temporary internet files a new jpg cookie of which the text started with ?? and then continued with the folder path! Some other cookies contain information of the registry.

All this just happens when I&#039;m logged into my gmail account.

I&#039;m completely lost cause I&#039;m no technician at all. I don&#039;t know what to do.

I tried to call up Google Germany but there&#039;s just an answering machine which says &quot;no support&quot;.</description>
		<content:encoded><![CDATA[<p>Hello,<br />
I know &#8220;nothing&#8221; about programming but urgently need help! My contact list and parts of emails are spyed out (storaged in cookies)!!! </p>
<p>Last Thursday I was logged into my gmail account when suddenly everything slowed down and certain functions like &#8220;compose&#8221; didn&#8217;t work anymore.</p>
<p>I clear out my folder &#8220;temporary internet files&#8221; once or twice a day. When gmail wasn&#8217;t working properly I logged in and out and switched to the folder &#8220;temporary internet files&#8221;.</p>
<p>I saw that a CONTACT ADDRESS which I didn&#8217;t use for about 3 years was  part of the text of a cookie. I cleared the folder but when I logged in again there was the same cookie. </p>
<p>Same happened with about 20 other contacts, most of them I didn&#8217;t use for years!</p>
<p>I then cleared my contact list.</p>
<p>Then it was getting even scarier: Parts of old message and data were part of new created cookies.</p>
<p>There are other cookies which show symbols like ?????????, %%%% or squares. </p>
<p>The most extreme which happened then was: I did screenshots of the suspicious cookies to have some sort of  documentation. I storaged these screenshots in a completely different folder. Suddenly there was in the folder temporary internet files a new jpg cookie of which the text started with ?? and then continued with the folder path! Some other cookies contain information of the registry.</p>
<p>All this just happens when I&#8217;m logged into my gmail account.</p>
<p>I&#8217;m completely lost cause I&#8217;m no technician at all. I don&#8217;t know what to do.</p>
<p>I tried to call up Google Germany but there&#8217;s just an answering machine which says &#8220;no support&#8221;.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
