orkut-logo Again the credit behind the discovery of this bug goes to Gaurav Dua. Just a day ago Gaurav mentioned on his blog, about how Orkut can be exploited to get mail id of any person, even if he/she is not in your friend’s list. I think this is a serious concern and should be checked immediately by Orkut team as there are many famous personalities present in Orkut, and you can surely imagine their fate if anyone gets their mail id.

Actually this is done by adding the targeted person as a friend. After you add them as your friend, no matter whether they accept the invitation or not, you just need to import your ‘contacts’ from the ‘friends’ tab present on your profile and you are done! The imported CSV file then reveals all mail ids even if the targeted person have not yet accepted your friend request. Detailed step by step procedure is mentioned here.

Personally I don’t think it ethical to get the mail ids of others without their permission. So I am thinking to report about this bug. What do you say?

Links: Step by step guide