Hacker discovers Gmail vulnerability that leaves any account open to compromise

Gmail logoA student and security researcher from Pakistan has found a serious issue with Gmail that makes it possible for a hacker to take over any email address.

The vulnerability relates to the way Google handles the linking of a primary Gmail account to another email address for the purposes of message forwarding. In just a few steps it was -- before Google fixed the problem -- possible to take over ownership of an email address by tricking the system into sending out the necessary verification code.

If a hacker knows a secondary email address associated with a Gmail account he is looking to compromise, Gmail can be fooled into sending the account verification email to any address. The person who found the flaw, Ahmed Mehtab, explains the conditions in which the flaw can be exploited:

  • If recipient's SMTP is offline
  • If recipient has deactivated his email
  • If recipient does not exist
  • If recipient exists but has blocked a user

Over on HackRead, Uzair Amir shares details of how an attack can be carried out:

The attacker tries to verify the ownership status of an email address by emailing Google. Google sends an email to that address for verification. The email address cannot receive the email and hence, Google’s mail is sent back to the actual sender and this time it contains the verification code. This verification code will be used by the hacker and the ownership to that particular address will be confirmed.

Or, as, Mehtab puts it:

  • Attacker tries to confirm ownership of xyz@gmail.com
  • Google sends email to xyz@gmail.com for confirmation
  • xyz@gmail.com is not capable of receiving email, so email is bounced back to Google
  • Google gives attacker a failure notification in his inbox with the verification code
  • Attacker takes that verification code and confirms his ownership to xyz@gmail.com

The video below goes into a little more detail:

Source: Betanews

Tags: break, Gmail, Google, security

Comments
Add comment

Your name:
Sign in with:
or
Your comment:


Enter code:

E-mail (not required)
E-mail will not be disclosed to the third party


Last news

 
The NVIDIA GeForce GTX 1180 will be Turing-based with a 12nm FinFET die shrink
 
This only works on posts made by profiles that are public
 
 
The device will be standalone and based on a Qualcomm chipset
 
Apple plans on offering a cheaper smart speaker that will be priced at $199
 
Chrome will adopt a new approach to indicating site security
 
Data shows they are leading smartphone sale worldwide
 
Is this an error or it is really happening?
The Samsung Galaxy A5 (2017) Review
The evolution of the successful smartphone, now with a waterproof body and USB Type-C
February 7, 2017 /
Samsung Galaxy TabPro S - a tablet with the Windows-keyboard
The first Windows-tablet with the 12-inch display Super AMOLED
June 7, 2016 /
Keyboards for iOS
Ten iOS keyboards review
July 18, 2015 /
Samsung E1200 Mobile Phone Review
A cheap phone with a good screen
March 8, 2015 / 4
Creative Sound Blaster Z sound card review
Good sound for those who are not satisfied with the onboard solution
September 25, 2014 / 2
Samsung Galaxy Gear: Smartwatch at High Price
The first smartwatch from Samsung - almost a smartphone with a small body
December 19, 2013 /
 
 

News Archive

 
 
SuMoTuWeThFrSa
  12345
6789101112
13141516171819
20212223242526
2728293031  




Poll

Do you use microSD card with your phone?
or leave your own version in comments (10)