Jump to content
YOUR-AD-HERE
HOSTING
TOOLS
992Proxy

Locked Vulnerability in Gmail allows to reset password of any account


hack3core

Recommended Posts

This is the hidden content, please

 

A security researcher named Oren Hafif

This is the hidden content, please
a
This is the hidden content, please
in the gmail accounts that could allow an attacker to hijack any email account.

This is a type of the password reset vulnerability, in the hacking process attacker have to send an email which looks like an email from an official google account.

 

It’s a simple spear-phishing attack by leveraging a number of flaws i.e Cross-site request forgery (CSRF), and cross-site scripting (XSS), and a flow bypass.

 

 

This is the hidden content, please

 

Upon clicking the link, it redirect users to a page that is linked to https.google.com but in real it leads the victim to the attacker’s website because of CSRF attack with a customized email address. In that page you have to enter, the last password you remember and a new password:

 

This is the hidden content, please

After completing the information collecting process—attacker has received your new password that you set for your account and cookie information of your account:

 

This is the hidden content, please

 

 

 

Share and Enjoy

 

This is the hidden content, please

Edited by Versus71
Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.