Again the credit behind the discovery of this bug goes to Gaurav Dua. Just a day ago Gaurav mentioned on his blog, about how Orkut can be exploited to get mail id of any person, even if he/she is not in your friend’s list. I think this is a serious concern and should be checked immediately by Orkut team as there are many famous personalities present in Orkut, and you can surely imagine their fate if anyone gets their mail id.
Actually this is done by adding the targeted person as a friend. After you add them as your friend, no matter whether they accept the invitation or not, you just need to import your ‘contacts’ from the ‘friends’ tab present on your profile and you are done! The imported CSV file then reveals all mail ids even if the targeted person have not yet accepted your friend request. Detailed step by step procedure is mentioned here.
Personally I don’t think it ethical to get the mail ids of others without their permission. So I am thinking to report about this bug. What do you say?
Links: Step by step guide
12 Comments
This is probably one of the reasons why I do not use Orkut email or even social networks email programs (like Facebook).
Their is more financial incentive for an email company to keep email secure than a social network to keep one feature secure.
Orkut users would be wise to simply have all of their Orkut messages automatically forward to their gmail/yahoo/hotmail/etc. accounts.
@Deepak
It doesn’t matter if you report this or not, the bug will be fixed very soon…
I tried this yest. didn’t work š
its not working….
@Sreejoy & @Gautam–
While posting this I tried it out personally…
It was working f9 for me..
Seems they have checked this bug š
@Mayur Somani –
Yea.. and from the above comments it seems the bug is fixed š
I like this it is good.
hai where u
this is a great work done by u.
Hi, im fron Brazil, can you help me extracts emails from orkut communities. i have been looking for this tool for a long time.
I want to know the email address of orkut user…who is not in my friend list.plz suggest.
orkut is a fabulus site