028

Google Security Passwords Security Gaps

The security researcher Oren Hafif discover some σημεία στη Google password recovery tools that could be used by malicious users to gain access to foreign accounts.

Attacks Phishing on Google are not uncommon, but the expert has managed to discover a very realistic way for such an attack and to use a number of shortcomings he found in the password recovery process.

Three different gaps have been exploited for this attack: one cross-site request forgery (CSRF), one cross-site scripting (XSS) and one flow bypass.

The expert published an attack scenario spear-phishing. The attacker sends the victim a fake "Account Ownership Confirmation" message that looks very much like a Gmail page.

The email asks the recipient to confirm ownership of the account by providing a username and password by clicking on a link. The connection that exists in the appears to be a google.com URL, but actually directs the victim to the attacker's website.

This is where the exploitation of vulnerabilities takes place.
Google has corrected vulnerabilities within 10 days of notification and will reward Hafif with 5.100 dollars.

Additional technical details about this attack are available on the Hafif blog.
Watch the video

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).