Gmail Security Flaw Proof of Concept
by Brandon
Sunday, November 23rd, 2008
Permalink

GC Update November 27th, 2008 5:22am

Aibek from makeuseof has commented stating that only one person involved in the recent filter-related domain heist was contacted by Google before they made an official statement on Tuesday.

“Nope they haven’t contacted me. I also talked to both Florin and Edin and only one of them was contacted by Google.”

###

OFFICIAL UPDATE FROM GOOGLE:

Gmail Security and Recent Phishing

We’ve seen some speculation recently about a purported security vulnerability in Gmail and the theft of several website owners’ domains by unauthorized third parties. At Google we’re committed to providing secure products, and we mounted an immediate investigation. Our results indicate no evidence of a Gmail vulnerability….

###

Is it possible for someone to create a malicious filter without having access to your Gmail username and password? No, however, they can force you to create the filter without your knowledge.

The blogosphere is buzzing about a Gmail Security Flaw that has caused some people to lose their domain names registered through GoDaddy. 

To understand how this exploit works let me first explain how I would carry it out (if I were a blackhat). Then we can move on and explain the exploit in detail. Let’s use a current example and assume that I was trying to steal MakeUseOf.com and I already knew it was registered by GoDaddy. Let’s also assume that I knew the owner’s Gmail address. I would want to create a filter like the one in the image above, where all email sent from GoDaddy Support was automatically deleted and forwarded to my email address.

Once the filter was setup I would simply head on over to GoDaddy’s Customer Number Retrieval page and enter the following info:

 

Once I press continue an email is sent to the domain owner’s email address but since I’ve setup a filter he never sees it in his inbox. Instead, it is sent to the trash and forwarded to my email address. With the GoDaddy Account Number I can now proceed to the GoDaddy Password Retrieval page:

 

 

Once again I simply press continue and an email containing an Authorization Code is sent the the owner’s email address but the filter deletes it immediately and forwards it on to me. I now have the ability to take over this person’s GoDaddy account and transfer MakeUseOf.com or any domain within that account to my registrar.
(more…)

Listen to Coldplay Prospekt’s March EP
by Brandon
Friday, November 14th, 2008
Permalink

Prospekts

Listen to Coldplay Prospekt’s

 

Glass of Water

Listen to Coldplay Glass of Water

 

Life in Technicolor ii

Listen to Coldplay Life in Technicolor ii

Checkout the release details on Coldplay.com