Header Ads

Pakistani Hacker Shows How Anyone Can Hack Gmail Account


Pakistani hacker has found a major vulnerability in Gmail’s verification process which can allow hackers to hack any email account.

Pakistani Hacker Shows How Anyone Can Hack Gmail Account

We all know that Google always supports fresh programmers, white hat hackers, and security researchers an opportunity to prove their skills and they also pay those researchers in Google’s Vulnerability Reward program.
Nowadays just to keep users safe against various cyber attacks, almost every giant company have implemented a bug bounty program in which the successful candidate is rewarded with the prize to discover any flaw or vulnerability in their services.
Recently, a Pakistani student and CEO of Security Fuse, Ahmed Mehtab was listed in Google’s Hall of Fame for discovering a major flaw in Gmail which allows anyone to hack any email account.
However, qualifying for Google’s VRP is never going to be easy so it becomes vital that the vulnerability/flaw is identified in any of these categories mentioned:
  • Cross-site scripting,
  • Cross-site request forgery,
  • Mixed-content scripts,
  • Authentication or authorization flaws,
  • Server-side code execution bugs
If the Flaw/Vulnerability seems to be the valid one then the researchers can expect to receive up to $20,000 from Google. Guess what! Ahmed Mehtab is the latest to win the prize money by Google.
Gmail allows users to set forwarding address so the emails which users receives are also sent to the another added the email address. Ahmed Mehtab said ” These two modules were actually vulnerable to authentication or verification bypass. It’s similar to account takeover but here I as an attacker can hijack email addresses by confirming the ownership of email and was able to use it for sending emails.”
Ahmed Mehtab Said in his blog Security Fuse that any email address could be hacked if it matches any of the following cases-
  • If recipients SMTP is offline
  • If recipient has deactivated his email
  • If recipient does not exist
  • If recipient exists but has blocked us
  • Cases could be even more

Further, Ahmed Mehtab discussed how the hack is carried out:

  • Attacker try’s to confirm ownership of xyz@gmail.com
  • Google sends email to xyz@gmail.com for confirmation
  • xyz@gmail.com is not capable of receiving email so email is bounced back to Google
  • Google gives attacker a failure notification in his inbox with the verification code
  • Attacker takes that verification code and confirms his ownership to xyz@gmail.com
Ahmed Mehtab also posted a video that was recorded at the time when it was vulnerable. However, he mentioned that he was not awarded for such a serious security issue but they listed him in Google’s Hall Of Fame for his contribution.

4 comments:

  1. Well after seeing the vulnerabilities in the Gmail system, google now should take steps to improve the security. It was already told them that there were flaws in their security.

    ReplyDelete
  2. Do you need to increase your credit score?
    Do you intend to upgrade your school grade?
    Do you want to hack your cheating spouse Email, whatsapp, Facebook, instagram or any social network?
    Do you need any information concerning any database.
    Do you need to retrieve deleted files?
    Do you need to clear your criminal records or DMV?
    Do you want to remove any site or link from any blog?
    you should contact this hacker, he is reliable and good at the hack jobs..
    contact : cybergoldenhacker at gmail dot com

    ReplyDelete
  3. If you ever want to change or up your university grades contact cybergolden hacker he'll get it done and show a proof of work done before payment. He's efficient, reliable and affordable. He can also perform all sorts of hacks including text, whatsapp, password decrypt,hack any mobile phone, Escape Bancruptcy, Delete Criminal Records and the rest

    Email: cybergoldenhacker at gmail dot com

    ReplyDelete

  4. If you ever want to change or up your university grades contact cybergolden hacker he'll get it done and show a proof of work done before payment. He's efficient, reliable and affordable. He can also perform all sorts of hacks including text, whatsapp, password decrypt,hack any mobile phone, Escape Bancruptcy, Delete Criminal Records and the rest

    Email: cybergoldenhacker at gmail dot com

    ReplyDelete

Powered by Blogger.