XSS, CSRF grants Gmail passwords

By
Follow google news

Bug fixed.

Google has fixed a security issue in its Gmail password recovery process which could leave users' passwords vulnerable to theft via social engineering.

XSS, CSRF grants Gmail passwords

Researcher Oren Hafif discovered the bug and demonstrated how to exploit it in a video.

Google's security team fixed the issue in 10 days.

By sending a victim a phishing email, designed to look like a password reset email from Google, an attacker could easily lead users to a malicious URL, setting the stage for exploit.

Hafif showed how a cross-site request forgery attack, followed by a cross-site scripting attack, could prompt Google to actually allow users to reset

their passwords under the watchful eyes of a saboteur.

This article originally appeared at scmagazineus.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

NAB's CSO to move to ANZ Banking Group

NAB's CSO to move to ANZ Banking Group

How a Texas student blew the whistle on a rogue AI hacking attempt

How a Texas student blew the whistle on a rogue AI hacking attempt

Researchers chain Tesla charger bug into a four-vendor EV worm

Researchers chain Tesla charger bug into a four-vendor EV worm

Two Aussies alleged to be "principal participants" of TeamPCP hacking group

Two Aussies alleged to be "principal participants" of TeamPCP hacking group

Log In

  |  Forgot your password?