-
12-20-2011, 11:08 PM #1Security Researcher
- Join Date
- Nov 2010
- Posts
- 150
- Blog Entries
- 1
- Thanks
- 41
- Thanked 45 Times in 26 Posts
Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploit
#Title: Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploitation)
#Author: Sandeep Kamble (www.SandeepKamble.com)
#Risk Factor: Low (Why low please read below)
#Attack Type: A User can access B User account Link to remove secondary E-mail address
#Reported Date: OCT 21 , 2011
Overview:
In Google account setting page, when you reset Google account password, it send Reset Password link to your secondary email address. Into that mail there is one more link which can be used remove your secondary email address.
Vulnerability Description:
This Vulnerability can be used to remove secondary email address. In this vulnerability we needed to guess ?C variable token to access the any users account link that can be used to remove secondary email address ?C variable token is generating at sever side so that it is not possible to guess this token and so that it can be performed at victim side only. (Self Exploitation)
Vulnerable Link
https://www.google.com/accounts/Acco...z_7p8Z4B&hl=en
Link it has two options, one option is to remove the Secondary and one option to negated email removing operation.
The above like is accessible to everyone. We cannot generate the token number so we can find the token using
Google Dork: Inurul : /AccountDisavow?c=
If you click on the radio button, “No, I didn't create *******@gmail.com - remove my email address, ********@yahoo.com, from this Google Account. “ and then click continue it will remove the email and delete the link token.
This link will be dead, No one can access it again !
But if you click on the,” Yes, *******@gmail.com is my Google Account. ” and press continue.
When u Click on the this radio button the token is not getting deleted, so that may be pages are indexed into Google
Proof of Concept


Special thanks to Amol Naik , Anil , veenu bhai
Warm Regards
Sandeep Kamble
www.sandeepkamble.comLast edited by [s]; 12-22-2011 at 02:28 PM.
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
-
The Following 4 Users Say Thank You to [s] For This Useful Post:
amolnaik4 (12-21-2011), AnArKI (12-21-2011), fb1h2s (12-21-2011), prashant_uniyal (12-21-2011)
-
12-22-2011, 10:15 AM #2Security Researcher
- Join Date
- Nov 2010
- Posts
- 150
- Blog Entries
- 1
- Thanks
- 41
- Thanked 45 Times in 26 Posts
Updating status of this google vulnerability.. 3rd Bug Qualified...
Google Rewarded $100

/$
Sandeep
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
-
12-22-2011, 06:02 PM #3Garage Member
- Join Date
- Jul 2010
- Location
- localhost@mumbai
- Posts
- 145
- Blog Entries
- 1
- Thanks
- 16
- Thanked 4 Times in 3 Posts
Congratz sandeep .. keep this nice work going ..
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Spirit was turned 2 ashes ,soul endured so much pain..
now the darker time evanescence ,the fallen shall rise again.
-
12-22-2011, 06:31 PM #4Super Administrator

- Join Date
- Jul 2010
- Location
- London
- Posts
- 455
- Blog Entries
- 1
- Thanks
- 157
- Thanked 145 Times in 69 Posts
gr8 Sandeep......keep it coming.....lately G4H had become very Google friendly lol..
-
12-23-2011, 11:59 AM #5Garage Newcomer
- Join Date
- May 2011
- Location
- Localhost@mumbai
- Posts
- 32
- Thanks
- 1
- Thanked 9 Times in 4 Posts
good going ... ownage

Thumbs up
LinkBacks (?)
-
Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploit
Refback This thread12-21-2011, 01:01 PM -
Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploit
Refback This thread12-21-2011, 10:53 AM -
Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploit
Refback This thread12-20-2011, 11:53 PM



8Likes
LinkBack URL
About LinkBacks



Reply With Quote

Research Resources for MS...
Today, 12:25 PM in Web Application Penetration Testing