Saturday, June 16, 2007

Latest Google Exploits


᠌᠌᠌
12:08 pm(4 hours ago) quote
Latest Google Exploits...
Until Google disables this. This link would work…

If a “user” is logged into his gmail account. and for SOME reason visits this link (dont ask me how.. send him/her an email with an invite to googlegroups… but has a hidden hyperlink)... His/Her ENTIRE addressbook, loginid, auth token, other google account info/ address book COULD be captured and sent to LOL.. somone like me :-)

The URL here DOES not send me any info.. but think about it, I could use this “script” to capture the “visible” info redirect the user back to google groups… so basically.. I end up having all “your” info without you knowing it…


On case you dont trust , please do log into gmail and then come back and click on this link…

http://groups-beta.google.com/groups/profile/contacts?out=js&show=ALL&psort=Affinity&callback=init&max=99999


PS: I am not Interested in these kind of activities, it's just that my fellas love doing it


᠌᠌᠌
12:10 pm(4 hours ago) quote
Guys! Subah Accha Din tha, Found One More

http://video.google.com/data/contacts?out=js&max=500%20&psort=Affinity&callback=getContacts

no photo
Anonymous
12:10 pm(4 hours ago) quote
but not for children
dont play with the link


tanush shukla
12:11 pm(4 hours ago) quote
how can we redirect so that we can get this inf


᠌᠌᠌
12:12 pm(4 hours ago) quote
Yea

Warning Kids : Dont play With This


᠌᠌᠌
12:13 pm(4 hours ago) quote
tanush shukla's Quoted message @ 12:11 pm (1 minute ago)

how can we redirect so that we can get this inf



no photo
Anonymous
12:15 pm(4 hours ago) quote
i saved the first link yesterday
it gave me all my contacts info of the profile which was deleted from orkut

amazing


᠌᠌᠌
12:18 pm(4 hours ago) quote
†✾►§σµℓ Яєค√єя◄✣'s Quoted message @ 12:15 pm (1 minute ago)

i saved the first link yesterday
it gave me all my contacts info of the profile which was deleted from orkut

amazing


Google has so many bugs and loops within..They are a bad company - ever heard yahoo ke saath ched chad, anyways i am a big time google fan


12:19 pm(4 hours ago) quote


Whiz
12:21 pm(4 hours ago) quote
me too...

tanush shukla
12:23 pm(4 hours ago) quote
PLZ TELL ME NA






᠌᠌᠌
Jun 16(2 days ago)
Warning To Kids - Don't Play With This

no photo
Anonymous
Jun 16(2 days ago)
^^^^
lolss


C™ Zohaib
Jun 16(2 days ago)


:๓ย:●| ŚÁßĨĤ |●
Jun 16(2 days ago)




Rodrigo Lacerda
Jun 16(2 days ago)
xml version
http://groups-beta.google.com/groups/profile/contacts?out=xml&show=ALL&psort=Affinity&callback=init&max=99999


Rodrigo Lacerda
Jun 16(2 days ago)
or only
http://groups-beta.google.com/groups/profile/contacts

xD

cool


fa
Jun 16(2 days ago)

nice... thanx for the info jerry ...


᠌᠌᠌
Jun 16(2 days ago)
Found one More

http://video.google.com/data/contacts?out=js&max=500%20&psort=Affinity&callback=getContacts


♥.♥Mr.¢σσℓ ®- ™♥
Jun 16(2 days ago)
gr8

Rodrigo Lacerda
Jun 16(2 days ago)
I search about this in google, and I found somethings...

this is a old bug that was fixed yet
you only needed visit any web site, and your whole contact list could be stealed






but

Have a look at the very first thing in that javascript:

while(true);

.
If that URL were ever to be set as the src attribute of a javascript tag, it would cause the browser to infinitely loop, and the webpage including it would not be able to read any of the data.

So while google has had issues with JSON being able to be included by malicious websites previously, it seems that they've fixed them.


thnx to kuza55 from sla.ckers