main
Report a problem

Froogle/Gmail Hack Warning

dbfriends   on 14 January 2005 - 11:55 · 27 comments & 14628 views

Advertisement (Why?)
Thanks to Aviran on BPN

An Israeli hacker has uncovered a flaw in Froogle, Google's price-comparison service, which could allow access to users' Gmail accounts. Nir Goldshlager, who discovered the flaw, warned that URL-embedded Javascript could end up causing personal information to be revealed.

If users execute the script by clicking a link, they would be redireted to a malicious website. From there, hackers can read a user's cookie. It may contain personal information, such as purchase histories, or the username and password used to access Google services - such as Gmail.

Goldshlager warned that even if the user chooses not to save the cookie, the hacker can still discover the username and password for other services such as Google Alerts and Groups because of the way that data is stored.

View: Neowin discussion thread
View: Froogle | Gmail

Post a comment · Send to friend Comments · There are 27 additional comments
#1 vetBroChaos on 14 Jan 2005 - 16:23
that guys last name can't really be Goldschlager....

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)