Hacker discovers Gmail vulnerability that leaves any account open to compromise

Gmail logoA student and security researcher from Pakistan has found a serious issue with Gmail that makes it possible for a hacker to take over any email address.

The vulnerability relates to the way Google handles the linking of a primary Gmail account to another email address for the purposes of message forwarding. In just a few steps it was -- before Google fixed the problem -- possible to take over ownership of an email address by tricking the system into sending out the necessary verification code.

If a hacker knows a secondary email address associated with a Gmail account he is looking to compromise, Gmail can be fooled into sending the account verification email to any address. The person who found the flaw, Ahmed Mehtab, explains the conditions in which the flaw can be exploited:

  • If recipient's SMTP is offline
  • If recipient has deactivated his email
  • If recipient does not exist
  • If recipient exists but has blocked a user

Over on HackRead, Uzair Amir shares details of how an attack can be carried out:

The attacker tries to verify the ownership status of an email address by emailing Google. Google sends an email to that address for verification. The email address cannot receive the email and hence, Google’s mail is sent back to the actual sender and this time it contains the verification code. This verification code will be used by the hacker and the ownership to that particular address will be confirmed.

Or, as, Mehtab puts it:

  • Attacker tries to confirm ownership of xyz@gmail.com
  • Google sends email to xyz@gmail.com for confirmation
  • xyz@gmail.com is not capable of receiving email, so email is bounced back to Google
  • Google gives attacker a failure notification in his inbox with the verification code
  • Attacker takes that verification code and confirms his ownership to xyz@gmail.com

The video below goes into a little more detail:

Source: Betanews

Tags: break, Gmail, Google, security

Add comment

Your name:
Sign in with:
Your comment:

Enter code:

E-mail (not required)
E-mail will not be disclosed to the third party

Last news

Consumer group recommends iPhone 8 over anniversary model
LTE connections wherever you go and instant waking should come to regular PCs, too
That fiction is slowly becoming a reality
The Snapdragon 845 octa-core SoC includes the Snapdragon X20 LTE modem
Human moderators can help make YouTube a safer place for everyone
Google says Progressive Web Apps are the future of app-like webpages
All 2018 models to sport the 'notch'
The biggest exchange in South Korea, where the BTC/KRW pair is at $14,700 now
The Samsung Galaxy A5 (2017) Review
The evolution of the successful smartphone, now with a waterproof body and USB Type-C
February 7, 2017 /
Samsung Galaxy TabPro S - a tablet with the Windows-keyboard
The first Windows-tablet with the 12-inch display Super AMOLED
June 7, 2016 /
Keyboards for iOS
Ten iOS keyboards review
July 18, 2015 /
Samsung E1200 Mobile Phone Review
A cheap phone with a good screen
March 8, 2015 / 4
Creative Sound Blaster Z sound card review
Good sound for those who are not satisfied with the onboard solution
September 25, 2014 / 2
Samsung Galaxy Gear: Smartwatch at High Price
The first smartwatch from Samsung - almost a smartphone with a small body
December 19, 2013 /

News Archive



Do you use microSD card with your phone?
or leave your own version in comments (4)