PDA

View Full Version : Vulnerability in Gmail



rareyush
01-30-2011, 04:43 AM
Vulnerability in Gmail

Credits To: DarkStarOne

Gmail is one of the major webmail service provider across the globe. But as we all know Gmail still carries that 4 letter word BETA. Sometimes we may wonder, why Gmail is still in the testing stage even after years of it’s emergence. Here is one small reason for that.

Gmail follows a strict rule that doesn’t allow it’s users to have their first or the last namecontain the term Gmail or Google.

That is, while signing up for a new Gmail account the users cannot choose a first or last name that contains the term Gmail or Google. You can see this from the below snapshot

http://www.ethicalhacking1.com/eh1images/gmail2.JPG


This rule is implemented by Gmail for obvious reasons, because if the users are allowed to keep their first or the last name that contains the term Gmail or Google, then it is possible to easily impersonate the identity of Gmail (or Gmail Team) and engage themselves in phising or social engineering attacks on the innocent users. This can be done by simply choosing the first and last name with the following combinations.


First Name Last Name
Gmail Team
Google Team
Gmail Password Assistance

From the above snapshot we can see that, Gmail has made a good move in stopping the users from abusing it’s services. However this move isn’t just enough to prevent the malicious users from impersonating the Gmail’s identity.

Because Gmail has a small vulnerability that can be exploited so that the users can still have their name contain the terms Gmail or Google. You may wonder how to do this. But it’s very simple.

1. Login to your Gmail account and click on Settings.

2. Select Accounts tab

3. Click on edit info

4. In the Name field, select the second radio button and enter the name of your choice. Click on Save Changes and you’re done!

Now, Gmail accepts any name even if it contains the term Google or Gmail. You can see from the below snapshot

http://www.ethicalhacking1.com/eh1images/gmail3.JPG

Allowing the users to have their names contain the terms Gmail or Google is a serious vulnerability even though it doesn’t seem to be a major one.

This is because a hacker or a malicious attacker can easily exploit this flaw and send phishing emails to other Gmail users asking for sensitive information such as their passwords.

Most of the users don’t even hesitate to send their passwords since they believe that they are sending it to Gmail Team (or someone authorized). But in reality they are sending it to an attacker who uses these information to seek personal benefits.

So the bottomline is, if you get any emails that appears to have come from the Gmail Team or similar, don’t trust them! Anyone can send such emails to fool you and take away your personal details.

Hope that Gmail will fix this vulnerability as soon as possible to avoid any disasters.

Bynaks
01-30-2011, 01:37 PM
you got that right, i hope they fix it asap, i also lost my account recently

Charlie
01-31-2011, 09:53 PM
Wow you find that out ?

KaNoN7
02-11-2011, 10:33 PM
nice thx you

Zabova
02-12-2011, 09:51 PM
Thank you/

Blackshadow
02-14-2011, 03:52 AM
Nice bro thanks !!

blackice
02-14-2011, 07:27 AM
Wow will need to keep a closer eye on who i am sending my account info to now, I hope google has fixed this already!

inggity
02-14-2011, 08:23 AM
nice thx you

prits_u009
02-24-2011, 05:42 AM
thanksss bro

mhdri
02-25-2011, 08:52 PM
wawwwwwwwwwwwwww good

Gembel X-Secutive
02-26-2011, 03:03 PM
Great Post My Brother
thanks http://www.freeworldnow.com/boy%20kisses%20Koran.jpg

SaEaS
02-26-2011, 09:44 PM
thnx brother

koas
02-26-2011, 11:42 PM
nice thanks bro!

xbritvax
03-03-2011, 07:01 PM
nice thx you

exe
03-05-2011, 04:53 AM
thank you 1

exe
03-05-2011, 04:57 AM
thankss .

PersusReload
03-07-2011, 11:47 AM
Interessting read thanx

cado
03-10-2011, 11:33 PM
good good bro

cado
03-10-2011, 11:33 PM
apreciate !

FD GOD
03-12-2011, 02:15 AM
dont try you will be banned lol

rayodark
03-12-2011, 10:43 PM
oh nice information

AdRyAnOTeAm
03-13-2011, 06:34 PM
woow.......

lock
03-19-2011, 10:32 AM
thank's !! for share !!

saidinh0
03-19-2011, 12:02 PM
nice trun man

thobias
03-19-2011, 03:42 PM
google will fix it soon

PentoZ
03-20-2011, 03:39 AM
nice found thanks