028

Google Security Passwords Security Gaps

The security researcher Oren Hafif discover some σημεία στη διαδικασία ανάκτησης κωδικού πρόσβασης της Google που θα μπορούσαν να χρησιμοποιηθούν από κακόβουλους to access foreign accounts.

Attacks Phishing on Google are not unusual, but the expert managed to discover a very realistic way for such and use a number of flaws it identified in the password recovery process.

Three different ones have been exploited for this attack: one cross-site request forgery (CSRF), one cross-site scripting (XSS) and one flow bypass.

The expert published an attack scenario spear-phishing. The attacker sends the victim a fake "Account Ownership Confirmation" message that looks very much like a Gmail page.

The email asks the recipient to confirm the ownership of the account by providing username and password by clicking on a link. The link in the email appears to be a google.com URL, but it actually leads the victim to the attacker's website.

This is where the exploitation of vulnerabilities takes place.
Google has corrected vulnerabilities within 10 days of notification and will reward Hafif with 5.100 dollars.

Additional technical details about this attack are available on the Hafif blog.
Watch the video

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).