• $
  • £

Massive flaw revealed the email address of EVERY user

Massive flaw revealed the email address of EVERY user
12.06.2014 22:58
A massive security flaw in Google's Gmail service that could have been used to extract millions of addresses has been revealed.

The flaw was only found when an Israeli security researchers raised the alarm with Google.The search giant said the flaw has now been fixed - and paid the researcher for his tip.Oren Hafif says the trick would not have exposed passwords or otherwise allowed easy access to those accounts, but could have left users vulnerable to spam, phishing or password-guessing attacks.'I bruteforced a token in a Gmail URL to extract all of the email addresses hosted on Google,' he revealed in a blog this week.'I could have done this potentially endlessly,' says Hafif, a Tel Aviv, Israel-based penetration tester for security firm Trustwave, told Wired.'I have every reason to believe every Gmail address could have been mined.'The exploit wouldn’t have just affected personal users of Gmail, Hafif said, but also every business that uses Google to hosts its email, including even Google itself.The exploit uses a sharing feature of Gmail that allows a user to “delegate” access to their account. By tweaking the web address, Hafif found it was possible to reveal a random user's email address.By automating the character changes with a piece of software called DirBuster, he was able to collect 37,000 Gmail addresses in about two hours.Hafif says it took Google another month after his report to fix the bug.The company initially declined to pay him under its bug bounty program for rewarding hackers who expose and help fix its security flaws. But it later relented and paid him $500.A Google spokesman confirms that the company patched Hafif’s email-stealing bug and paid him a reward for his help, but declined to respond to requests for further comment.Hafif also admitted he has no idea if the flaw had been used.'We’ll never know,' he said.(dailymail.co.uk)Bakudaily.az

Similar news
Similar news
China sent 280 container trains to Europe via Middle Corridor since early 2024
Business 16:09
China sent 280 container trains to Europe via Middle Corridor since early 2024
Azerbaijan and Ukraine explore avenues for deepening economic ties
Business 17:30
Azerbaijan and Ukraine explore avenues for deepening economic ties
Azerbaijan imports $900M worth of goods from Türkiye in 5 months
Business 13:30
Azerbaijan imports $900M worth of goods from Türkiye in 5 months
35 projects implemented in liberated territories of Azerbaijan in 2023
Business 16:00
35 projects implemented in liberated territories of Azerbaijan in 2023
Israeli companies invited to investment projects in Karabakh’s industrial parks
Business 18:30
Israeli companies invited to investment projects in Karabakh’s industrial parks
Italian firms interested in participating in projects to be implemented in Karabakh
Business 14:00
Italian firms interested in participating in projects to be implemented in Karabakh
Azerbaijani economy minister, governor of St. Petersburg mull enhancing joint activities in shipbuilding
Business 15:00
Azerbaijani economy minister, governor of St. Petersburg mull enhancing joint activities in shipbuilding
Russia-Azerbaijan trade reaches $4.4 billion, Russian ambassador says
Business 10:00
Russia-Azerbaijan trade reaches $4.4 billion, Russian ambassador says
Azerbaijan to increase value of non-oil exports to $5B by 2026
Business 14:00
Azerbaijan to increase value of non-oil exports to $5B by 2026
Anews TV

Our official Youtube channel

Subscribe