New issue
Advanced search Search tips

Issue 604857 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: mail can be sent without authentication

Reported by soumya.u...@gmail.com, Apr 19 2016

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs


VULNERABILITY DETAILS
Please provide a brief explanation of the security issue.

VERSION
Chrome Version: [x.x.x.x] + [stable, beta, or dev]
Operating System: [WINDOWS 10]



REPRODUCTION CASE

Mail can be send from any account without authorization using external relay server. The account user is not aware that the mail has been sent from their account.


 

Comment 1 by vakh@chromium.org, Apr 19 2016

Status: ExternalDependency (was: Unconfirmed)
Hi soumya.upadhyay6@gmail.com, thanks for filing the issue.
Could you please provide a list of steps to follow to be able to reproduce this issue? That would help in triaging this issue further.
Labels: Needs-Feedback
Status: Unconfirmed (was: ExternalDependency)

Comment 3 by vakh@chromium.org, Apr 20 2016

Labels: -Needs-Feedback
Status: WontFix (was: Unconfirmed)
Marking as WontFix for now. Please feel free to re-open with a list of steps to follow to be able to reproduce this issue.
Hello,

I was able to send mail from any account to any my account without that
user's authorization. The user cant see the mail he/she sent in their sent
box but the mail appears in my inbox.

I was able to do this by writing a piece of java code and using a third
party relay server.

If you want i can send you some examples.

Thanks.
Soumya

Comment 5 by vakh@chromium.org, Apr 20 2016

Hi Soumya, thanks for writing back.
Please feel free to attach your code to this issue. In addition, please include a detailed list of steps for us to be able to reproduce the issue.
Unfortunately, without a reliable way to reproduce the issue, we won't be able to make any progress on it.
Sure. I will do that
I am attaching my code. My code will involve some of the jar files that you need to have before executing it. You can put other email ids in the input area in the code. For now, I have checked it for gmail only.
If the email doesn't appear in the main inbox, check spam.

And if you get any exception after compiling and executing, please send me full details. I am attaching mail.jar.
mail.jar
508 KB Download
SendEmail.java
2.1 KB View Download
Project Member

Comment 9 by sheriffbot@chromium.org, Jul 28 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment