March 12, 2004
Plaxo considered insecure

I've never been much on centralized contact managers like Plaxo. Why would I want to outsource all of my contacts to some company in the naïve hope that they won't hose me? Turns out that this may have been a legitimate concern; this describes a trivial script injection attack against Plaxo that lets an attacker 0wn your contact data. Oops. So, if you're using Plaxo, you should probably stop.

Posted by Paul at March 12, 2004 01:40 PM
Trackback Pings

TrackBack URL for this entry:
http://www.robichaux.net/cgi-bin/mt-tb.cgi/999

Comments

Post a comment




Remember Me?

(you may use HTML tags for style)

<