Jump to content

Massive flaw could have exposed every Gmail user’s address

NoBody

White-hat hacker found exploit that could allowed him to collect every gmail address registered. No passwords, no anything else, just addresses. Still, that list could be worth millions on black market, but Google gave him only 500$ for finding the exploit.

 

 

 

However, before Hafif notified Google, he successfully retrieved some 37,000 addresses from the system.

 

 

A Google spokesperson confirmed to Wired that the company had repaired the bug and awarded him some financial compensation. However, Google did not respond to any further requests for comment.

 

 

 

Google rewarded Hafif with $500 – which some commentators deemed to be very low considering the work he did.


“Being a good person is not very profitable these days :) ,” Hafif posted on Twitter on Thursday.

 

 

I think Google could be more fair in this one.

 

 

Source:

 

 

http://www.timesofisrael.com/israeli-expert-saves-gmail-from-killer-hack/

 

http://rt.com/news/165552-gmail-bug-users-address/

Link to comment
Share on other sites

Link to post
Share on other sites

Prepare for incoming spam...

The stone cannot know why the chisel cleaves it; the iron cannot know why the fire scorches it. When thy life is cleft and scorched, when death and despair leap at thee, beat not thy breast and curse thy evil fate, but thank the Builder for the trials that shape thee.
Link to comment
Share on other sites

Link to post
Share on other sites

Wow, I've seen Google+ , but i've never seen them be such assholes before.

Link to comment
Share on other sites

Link to post
Share on other sites

At least they gave him something that isn't prison.

A Romanian hacker once discovered an exploit in Google security's system and then he went to jail D: .

i5 4670k @ 4.2GHz (Coolermaster Hyper 212 Evo); ASrock Z87 EXTREME4; 8GB Kingston HyperX Beast DDR3 RAM @ 2133MHz; Asus DirectCU GTX 560; Super Flower Golden King 550 Platinum PSU;1TB Seagate Barracuda;Corsair 200r case. 

Link to comment
Share on other sites

Link to post
Share on other sites

It's difficult to figure out what is fair tbh.. Wouldn't surprise me if he didn't get anything at all. After all it's general feedback from a customer...
It's more than fair, and the fact they even paid him anything for it I think is great.

It all comes down to if he plans on using these 37k gmail accounts for anything..... 

Everyone have a cool signature. I don't, so I thought I would write something.

- Cool right?

Link to comment
Share on other sites

Link to post
Share on other sites

At least they gave him something that isn't prison.

A Romanian hacker once discovered an exploit in Google security's system and then he went to jail D: .

Depends on what he did with the flaw - if he exposed it for anyone to use, I could imagine google wouldn't be very happy about him.

Everyone have a cool signature. I don't, so I thought I would write something.

- Cool right?

Link to comment
Share on other sites

Link to post
Share on other sites

Honestly, Gmail's spam filter is so good that I haven't seen a spam message in my main mailbox for about 6 years.... So yeah, not worried at all.

QUOTE ME OR I PROBABLY WON'T SEE YOUR RESPONSE 

My Setup:

 

Desktop

Spoiler

CPU: Ryzen 9 3900X  CPU Cooler: Noctua NH-D15  Motherboard: Asus Prime X370-PRO  RAM: 32GB Corsair Vengeance LPX DDR4 @3200MHz  GPU: EVGA RTX 2080 FTW3 ULTRA (+50 core +400 memory)  Storage: 1050GB Crucial MX300, 1TB Crucial MX500  PSU: EVGA Supernova 750 P2  Chassis: NZXT Noctis 450 White/Blue OS: Windows 10 Professional  Displays: Asus MG279Q FreeSync OC, LG 27GL850-B

 

Main Laptop:

Spoiler

Laptop: Sager NP 8678-S  CPU: Intel Core i7 6820HK @ 2.7GHz  RAM: 32GB DDR4 @ 2133MHz  GPU: GTX 980m 8GB  Storage: 250GB Samsung 850 EVO M.2 + 1TB Samsung 850 Pro + 1TB 7200RPM HGST HDD  OS: Windows 10 Pro  Chassis: Clevo P670RG  Audio: HyperX Cloud II Gunmetal, Audio Technica ATH-M50s, JBL Creature II

 

Thinkpad T420:

Spoiler

CPU: i5 2520M  RAM: 8GB DDR3  Storage: 275GB Crucial MX30

 

Link to comment
Share on other sites

Link to post
Share on other sites

I hate white hackers!   see he could make much money on black market but he helped google and they gave him only 500$   

 

Pirates are real hackers. Who give us free games. why the fuck i must pay 60$ for shit like watch dogs and etc. if they were making games like CRYSIS 3 or BF4 i would buy but for shit like NFS rival. racing game that does not support racing wheel facepalm!  It's locked at 30 FPS and does not have pause LOL

 

God Bless Pirates!!!

Computer users fall into two groups:
those that do backups
those that have never had a hard drive fail.

Link to comment
Share on other sites

Link to post
Share on other sites

I hate white hackers!   see he could make much money on black market but he helped google and they gave him only 500$   

 

Pirates are real hackers. Who give us free games. why the fuck i must pay 60$ for shit like watch dogs and etc. if they were making games like CRYSIS 3 or BF4 i would buy but for shit like NFS rival. racing game that does not support racing wheel facepalm!  It's locked at 30 FPS and does not have pause LOL

 

God Bless Pirates!!!

 

I don't think you understand the ethics behind being a white hat, also  you are mixing the Warez scene with black hats.

 

There are pirates who crack a game's launcher and bypasses the security check. They don't get anything in return.

 

There are "pirates" who are named so because they torrent games or movies.

 

There are pirates who infiltrate and compromise million dollars networks, those are real black hats. They don't do it for fun, they do it for money.

 

There are script kiddies, 14yo who just learned how to crack WEP's and are already shitting themselves.

 

Stop calling everyone a pirate

Link to comment
Share on other sites

Link to post
Share on other sites

I mean those pirates who upload games until they have come out. or after they come out and who cracks it. one guy on guru3D makes watch dogs look like it was in 2012 at E3 :) 

 

thanks to Fenix who cracked BF3 so everyone can make his own server right on his desktop like i had! (i got bored) i had ping 0! on my server :) that was funny. 

 

thanks who cracks windows and programs. i would have payed 100-300$ for shitty windows (even free UBUNTU 14.04 beats it in every aspect except gaming but not for long) and 1000$ for other software. 

Computer users fall into two groups:
those that do backups
those that have never had a hard drive fail.

Link to comment
Share on other sites

Link to post
Share on other sites

He deserves at least $10,000, to be honest. Since I use GMail as my main email, I'm honestly disappointed that they gave him that little to save my email's security and 37,000 others. Fuck you Google.

Main rig on profile

VAULT - File Server

Spoiler

Intel Core i5 11400 w/ Shadow Rock LP, 2x16GB SP GAMING 3200MHz CL16, ASUS PRIME Z590-A, 2x LSI 9211-8i, Fractal Define 7, 256GB Team MP33, 3x 6TB WD Red Pro (general storage), 3x 1TB Seagate Barracuda (dumping ground), 3x 8TB WD White-Label (Plex) (all 3 arrays in their respective Windows Parity storage spaces), Corsair RM750x, Windows 11 Education

Sleeper HP Pavilion A6137C

Spoiler

Intel Core i7 6700K @ 4.4GHz, 4x8GB G.SKILL Ares 1800MHz CL10, ASUS Z170M-E D3, 128GB Team MP33, 1TB Seagate Barracuda, 320GB Samsung Spinpoint (for video capture), MSI GTX 970 100ME, EVGA 650G1, Windows 10 Pro

Mac Mini (Late 2020)

Spoiler

Apple M1, 8GB RAM, 256GB, macOS Sonoma

Consoles: Softmodded 1.4 Xbox w/ 500GB HDD, Xbox 360 Elite 120GB Falcon, XB1X w/2TB MX500, Xbox Series X, PS1 1001, PS2 Slim 70000 w/ FreeMcBoot, PS4 Pro 7015B 1TB (retired), PS5 Digital, Nintendo Switch OLED, Nintendo Wii RVL-001 (black)

Link to comment
Share on other sites

Link to post
Share on other sites

It is clearly stated the value that you would be given if you find a common web-problem

 

http://www.google.ca/about/appsecurity/reward-program/

 

To be honest $500 isn't that bad for just being able to get gmail usernames...it isn't like much was compromised

 

If someone creates full list of accounts... Trust me, its bad. Not necessarily from the user's point of view but as someone who does IT security, this is major flaw. Especially when you're talking about one of the largest email providers. 

 

If that list would for example go public, suddenly every script kiddie can sent bunch of spam to gmail servers and in result, google servers have additional unnecessary load and traffic + spam filters get less accurate (more people sending -> more chance for spam filter to fail and more time for google to detect it).

 

And that is only one of possible scenarios. Don't forget that people can get very creative with that kind of list.

Link to comment
Share on other sites

Link to post
Share on other sites

I wonder if he could have gotten more than $500 on the black market for the information he found. Apparently, that's what Google wants people to consider when they find something like this.

Case: NZXT H500i. Motherboard: Asus Prime Z390-A. CPU: i7 9700k OC @ 5.0GHz. GPU: EVGA 2080 FTW3 CPU Cooler: NZXT X62. Memory: G. Skill Ripjaws 32Gb 3200mhz. Storage: 1TB Samsung 840 EVO SSD /  120GB Samsung 840 EVO SSD  /  WD Caviar Black 3TB / WD Caviar Green 4TB. . PSU: Corsair AX760. Monitor: 2x Acer XB270HU. Keyboard: Corsair K70 RGB. Mouse: Corsair Glaive. 

Link to comment
Share on other sites

Link to post
Share on other sites

So I'd be more exposed

 

*looks at gmail*

 

-17 spam emails

-50 "social" updates

-50 "promotion" mails

 

And this is taking into account that this is supposed to be my "clean" email: I keep a yahoo account for all mail I suspect will be spam....

 

So....yeah it's almost impossible to use an email without spam, you need 2 or 3 or 4 accounts anyway. I can't imagine things getting much worst.

-------

Current Rig

-------

Link to comment
Share on other sites

Link to post
Share on other sites

So I'd be more exposed

 

*looks at gmail*

 

-17 spam emails

-50 "social" updates

-50 "promotion" mails

 

And this is taking into account that this is supposed to be my "clean" email: I keep a yahoo account for all mail I suspect will be spam....

 

So....yeah it's almost impossible to use an email without spam, you need 2 or 3 or 4 accounts anyway. I can't imagine things getting much worst.

Use google priority mail and actually flag things as spam. I did this for about a week and now all the important emails are in my inbox and everything else I never even look at.

FANBOY OF: PowerColor, be quiet!, Transcend, G.Skill, Phanteks

FORMERLY FANBOY OF: A-Data, Corsair, Nvidia

DEVELOPING FANBOY OF: AMD (GPUS), Intel (CPUs), ASRock

Link to comment
Share on other sites

Link to post
Share on other sites

This is a dictionary generated list jeez calm your tits everyone

 

Not like some nuclear missile launch codes or something

Link to comment
Share on other sites

Link to post
Share on other sites

So I'd be more exposed

 

*looks at gmail*

 

-17 spam emails

-50 "social" updates

-50 "promotion" mails

 

And this is taking into account that this is supposed to be my "clean" email: I keep a yahoo account for all mail I suspect will be spam....

 

So....yeah it's almost impossible to use an email without spam, you need 2 or 3 or 4 accounts anyway. I can't imagine things getting much worst.

 

I actually know a solution for you haha. If you use chrome, go get extension "MaskMe" (https://chrome.google.com/webstore/detail/maskme/dpkiidbpeijnaaacjlfnijncdlkicejg)

Basically what it does, it offers you to "mask" your email address at registration forms (you can manually create masked address it too). The way it works is: for example you want to register to a random forum -> you get on registration page -> at entering email address extension asks you if you want to use your real email or a masked one. If you choose a masked one, extension creates new xxxxxxx@opayq.com email address just for this site. When forum sends you confirmation link on masked email, it will forward it to you on your real address. If you see that this address is spaming you, you just click do not forward this masked email anymore. Say goodbye to spamers haha :P And the best thing is, you can see who is abusing their database :)

I found this extension a year ago and its GOLD for me, can not live without it :P. Surprisingly no one knows about it...

Link to comment
Share on other sites

Link to post
Share on other sites

I actually know a solution for you haha. If you use chrome, go get extension "MaskMe" (https://chrome.google.com/webstore/detail/maskme/dpkiidbpeijnaaacjlfnijncdlkicejg)

Basically what it does, it offers you to "mask" your email address at registration forms (you can manually create masked address it too). The way it works is: for example you want to register to a random forum -> you get on registration page -> at entering email address extension asks you if you want to use your real email or a masked one. If you choose a masked one, extension creates new xxxxxxx@opayq.com email address just for this site. When forum sends you confirmation link on masked email, it will forward it to you on your real address. If you see that this address is spaming you, you just click do not forward this masked email anymore. Say goodbye to spamers haha :P And the best thing is, you can see who is abusing their database :)

I found this extension a year ago and its GOLD for me, can not live without it :P. Surprisingly no one knows about it...

 

I used to have an even better extension way back called "bugmenot" which basically made generic login credentials available to all. This sounds like a good option, specially since my spam email is really getting out of control (1446 unread emails, all of it fucking spam)

-------

Current Rig

-------

Link to comment
Share on other sites

Link to post
Share on other sites

Hey, most companies would have sued him into oblivion, so at least there's that.

CPU: i7 3770k @ 4.8Ghz Motherboard: Sabertooth Z77 RAM: 16GB Corsair Vengeance GPU: GTX 780 Case: Corsair 540 Air Storage: 2x Intel 520 SSD Raid 0 PSU: Corsair AX850 Display(s): 1x 27" Samsung Monitor 3x 24" Asus Monitors Cooling: Swifttech H220 Keyboard: Logitech 710+ Mouse: Logitech G500 Headphones: Sennheiser HD 558 --- Internet: http://linustechtips.com/main/uploads/gallery/album_1107/gallery_12431_1107_23677.png My Setup:  http://linustechtips.com/main/gallery/image/7922-1-rkcf7io/ -- NAS: 3x WD Red 3TB Drives (RAIDZ-1), 5x 750gb Seagate ES HDD(RAIDZ-1), 120gb SSD for caching, OS: FreeNAS --  Server 1: Xeon E3 1275v2, 32GB of RAM, OS: ESXi 5.5 -- Server 2: Xeon E3 1220v2, 32GB of RAM, OS: ESXi 5.5

 

Link to comment
Share on other sites

Link to post
Share on other sites

All good haven't updated my email address in years ;-)

Rig 1 CPU: 3570K Motherboard: V Gene GPU: Power Color r9 280x at 1.35GHZ  RAM: 16 GB 1600mhz PSU: Cougar CMX 700W Storage: 1x Plexor M5S 256GB 1x 1TB HDD 1x 3TB GREEN HDD Case: Coolermaster HAFXB Cooling: Intel Watercooler
"My day so far, I've fixed 4 computers and caught a dog. Australian Tech Industry is weird."

"It's bent so far to the right, It's a hook."

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×