<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: GoogHOle (XSS pwning GMail, Picasa and almost 200K customers)</title>
	<link>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Mon, 22 Mar 2010 05:26:21 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Tort King</title>
		<link>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-13239</link>
		<dc:creator>Tort King</dc:creator>
		<pubDate>Thu, 11 Jun 2009 06:14:24 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-13239</guid>
		<description>You can't hack gmail.  That is b.s.  My computer guy said it isn't possible.  ticketslayer@gmail.com  LOL</description>
		<content:encoded><![CDATA[<p>You can&#8217;t hack gmail.  That is b.s.  My computer guy said it isn&#8217;t possible.  <a href="mailto:ticketslayer@gmail.com">ticketslayer@gmail.com</a>  LOL</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: karthi</title>
		<link>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7962</link>
		<dc:creator>karthi</dc:creator>
		<pubDate>Sat, 17 May 2008 15:05:12 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7962</guid>
		<description>hmm.. so.. noscript can block this type of attack??
hey.. besides, do you feel that i'm asking too many kiddie questions?? 
coz, i am a new born in this field..</description>
		<content:encoded><![CDATA[<p>hmm.. so.. noscript can block this type of attack??<br />
hey.. besides, do you feel that i&#8217;m asking too many kiddie questions??<br />
coz, i am a new born in this field..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7958</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Sat, 17 May 2008 13:49:12 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7958</guid>
		<description>@&lt;b&gt;karthi&lt;/b&gt;:
yes, they can, provided that the site is vulnerable to &lt;a href="http://noscript.net/faq#xss" rel="nofollow"&gt;XSS&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>@<b>karthi</b>:<br />
yes, they can, provided that the site is vulnerable to <a href="http://noscript.net/faq#xss" rel="nofollow">XSS</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: karthi</title>
		<link>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7957</link>
		<dc:creator>karthi</dc:creator>
		<pubDate>Sat, 17 May 2008 12:47:11 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7957</guid>
		<description>thank you giorgio..
i read on other blog that, one can hack my pwd by making me to click an image or some other links using javascript..
is it really possible?</description>
		<content:encoded><![CDATA[<p>thank you giorgio..<br />
i read on other blog that, one can hack my pwd by making me to click an image or some other links using javascript..<br />
is it really possible?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7949</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Fri, 16 May 2008 07:28:27 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7949</guid>
		<description>@&lt;b&gt;karthi&lt;/b&gt;:
No, nothing bad happens anymore because the bug has been fixed by Google.
But yes, that was how it used to work originally.</description>
		<content:encoded><![CDATA[<p>@<b>karthi</b>:<br />
No, nothing bad happens anymore because the bug has been fixed by Google.<br />
But yes, that was how it used to work originally.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: karthi</title>
		<link>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7947</link>
		<dc:creator>karthi</dc:creator>
		<pubDate>Fri, 16 May 2008 02:07:50 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7947</guid>
		<description>@Giorgio
OMG..
pls forgive my ignorance..
so, if someone opens the page when they are loggend onto gmail, the filter is set..?</description>
		<content:encoded><![CDATA[<p>@Giorgio<br />
OMG..<br />
pls forgive my ignorance..<br />
so, if someone opens the page when they are loggend onto gmail, the filter is set..?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7938</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Thu, 15 May 2008 14:29:23 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7938</guid>
		<description>@&lt;b&gt;karthi&lt;/b&gt;:
those links are not dead, it's just the vulnerability which has been fixed.
If you want to check how it used to work, you can just look at the source code:
view-source:http://beford.org/stuff/contacts.htm
view-source:http://beford.org/stuff/gmail.htm</description>
		<content:encoded><![CDATA[<p>@<b>karthi</b>:<br />
those links are not dead, it&#8217;s just the vulnerability which has been fixed.<br />
If you want to check how it used to work, you can just look at the source code:<br />
view-source:http://beford.org/stuff/contacts.htm<br />
view-source:http://beford.org/stuff/gmail.htm</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: karthi</title>
		<link>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7937</link>
		<dc:creator>karthi</dc:creator>
		<pubDate>Thu, 15 May 2008 13:42:49 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-7937</guid>
		<description>damn.. i came late to this info..
beford dot org leads me here..
the poc  link for &#34;stealing incoming messages&#34; are dead..
where can i find more information about that?</description>
		<content:encoded><![CDATA[<p>damn.. i came late to this info..<br />
beford dot org leads me here..<br />
the poc  link for &quot;stealing incoming messages&quot; are dead..<br />
where can i find more information about that?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Future is Fiction - Just another WordPress weblog &#187; Trust No One</title>
		<link>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-6240</link>
		<dc:creator>Future is Fiction - Just another WordPress weblog &#187; Trust No One</dc:creator>
		<pubDate>Wed, 20 Feb 2008 07:17:32 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-6240</guid>
		<description>[...] This is all a long lead-up to this link, from hackademix.net, about four recent security weaknesses in google. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] This is all a long lead-up to this link, from hackademix.net, about four recent security weaknesses in google. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: IT Security &#187; Blog Archive &#187; Gmail Cross Site Script Vulnerabilities Exposed</title>
		<link>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-903</link>
		<dc:creator>IT Security &#187; Blog Archive &#187; Gmail Cross Site Script Vulnerabilities Exposed</dc:creator>
		<pubDate>Thu, 25 Oct 2007 14:17:20 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/24/googhole-xss-pwning-gmail-picasa-and-almost-200k-customers/#comment-903</guid>
		<description>[...] Maone&#8217;s post at Hackademix.net also reports other Google XSS vulnerabilities that have recently come to light, targeting gmail, [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Maone&#8217;s post at Hackademix.net also reports other Google XSS vulnerabilities that have recently come to light, targeting gmail, [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
