+ Reply to Thread
Results 1 to 5 of 5
Like Tree8Likes
  • 4 Post By [s]
  • 3 Post By [s]
  • 1 Post By AnArKI

Thread: Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploit Share/Save - My123World.Com!

  1. #1
    [s]
    [s] is offline
    Security Researcher [s] is on a distinguished road [s]'s Avatar
    Join Date
    Nov 2010
    Posts
    150
    Blog Entries
    1
    Thanks
    41
    Thanked 45 Times in 26 Posts

    Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploit



    #Title: Google Email Recovery Vulnerability (Removing Secondary E-mail Address -Self Exploitation)
    #Author: Sandeep Kamble (www.SandeepKamble.com)
    #Risk Factor: Low (Why low please read below)
    #Attack Type: A User can access B User account Link to remove secondary E-mail address
    #Reported Date: OCT 21 , 2011


    Overview:

    In Google account setting page, when you reset Google account password, it send Reset Password link to your secondary email address. Into that mail there is one more link which can be used remove your secondary email address.

    Vulnerability Description:

    This Vulnerability can be used to remove secondary email address. In this vulnerability we needed to guess ?C variable token to access the any users account link that can be used to remove secondary email address ?C variable token is generating at sever side so that it is not possible to guess this token and so that it can be performed at victim side only. (Self Exploitation)

    Vulnerable Link

    https://www.google.com/accounts/Acco...z_7p8Z4B&hl=en
    Link it has two options, one option is to remove the Secondary and one option to negated email removing operation.
    The above like is accessible to everyone. We cannot generate the token number so we can find the token using

    Google Dork: Inurul : /AccountDisavow?c=

    If you click on the radio button, “No, I didn't create *******@gmail.com - remove my email address, ********@yahoo.com, from this Google Account. “ and then click continue it will remove the email and delete the link token.
    This link will be dead, No one can access it again !

    But if you click on the,” Yes, *******@gmail.com is my Google Account. ” and press continue.
    When u Click on the this radio button the token is not getting deleted, so that may be pages are indexed into Google

    Proof of Concept




    Special thanks to Amol Naik , Anil , veenu bhai

    Warm Regards

    Sandeep Kamble
    www.sandeepkamble.com
    Last edited by [s]; 12-22-2011 at 02:28 PM.

    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  2. The Following 4 Users Say Thank You to [s] For This Useful Post:

    amolnaik4 (12-21-2011), AnArKI (12-21-2011), fb1h2s (12-21-2011), prashant_uniyal (12-21-2011)

  3. #2
    [s]
    [s] is offline
    Security Researcher [s] is on a distinguished road [s]'s Avatar
    Join Date
    Nov 2010
    Posts
    150
    Blog Entries
    1
    Thanks
    41
    Thanked 45 Times in 26 Posts
    Updating status of this google vulnerability.. 3rd Bug Qualified... Google Rewarded $100



    /$
    Sandeep

    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

  4. #3
    Garage Member D4rk357 is on a distinguished road D4rk357's Avatar
    Join Date
    Jul 2010
    Location
    localhost@mumbai
    Posts
    145
    Blog Entries
    1
    Thanks
    16
    Thanked 4 Times in 3 Posts
    Congratz sandeep .. keep this nice work going ..

    To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

    Spirit was turned 2 ashes ,soul endured so much pain..
    now the darker time evanescence ,the fallen shall rise again.

  5. #4
    Super Administrator AnArKI will become famous soon enoughAnArKI will become famous soon enough AnArKI's Avatar
    Join Date
    Jul 2010
    Location
    London
    Posts
    455
    Blog Entries
    1
    Thanks
    157
    Thanked 145 Times in 69 Posts
    gr8 Sandeep......keep it coming.....lately G4H had become very Google friendly lol..
    fb1h2s likes this.

  6. #5
    Garage Newcomer Snypter is on a distinguished road
    Join Date
    May 2011
    Location
    Localhost@mumbai
    Posts
    32
    Thanks
    1
    Thanked 9 Times in 4 Posts
    good going ... ownage
    Thumbs up


Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts