Tech n' Cars Blogger Widgets

November 22, 2010

If  you had went on http://guntada.blogspot.com/, logged in to your Gmail account, the site would've harvested your Gmail account. And to prove it, the creator, Vahe, would've immediately sent you an email that would look like this:

Subject: Kinda Important Message...

Hello, please visit and share this link (I'm not sure exactly what the link is)
p.s. you received this message because you probably just visited this website already ;)
oh, hi google

But, Google took the site down. Imagine what somebody might be able to do if they can harvest your email like this. He probably had the capability of taking some of your information also! Just one more thing to show how dangerous the internet can get... Facebook would consider this just another feature of their website. Apparently, Google fixed the issue. They say:

"We quickly fixed the issue in the Google Apps Script API that could have allowed for emails to be sent to Gmail users without their permission if they visited a specially designed website while signed into their account. We immediately removed the site that demonstrated this issue, and disabled the functionality soon after. We encourage responsible disclosure of potential application security issues to security@google.com."

I wonder how many other problems you have in your system, Google.