New issue
Advanced search Search tips

Issue 838114 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner: ----
Closed: Apr 2018
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Major Security breach (Gmail ignores dot)

Reported by low...@gmail.com, Apr 30 2018

Issue description

since a while I'm having troubles with instagram, my password is modified by someonelse... 

Looking forward to this, i've discovered that an email@ gmail.com can be used with a 'dot' in the middle and it is still sent to the 'not dot email' : 

example: my mail : lowliv@gmail.com can be used for login to a website. 
a Hacker can create a mail like low.liv@gmail.com (with another name and surname) and the mail will be the same! 

I can send emails to all my google's account adding a '.' in and I still receiving the mail. 

So If I want to hack an account using gmail, I just have to create a similar account but with a 'dot (.)' inside and I will be able to reset any password! 

Well done !

(i'm waiting  on a feedback from your team )

Kind Regards 
Lowliv


 
Mergedinto: 699471
Status: Duplicate (was: Unconfirmed)
Summary: Major Security breach (Gmail ignores dot) (was: Major Security breach)
Thanks for the report. 

This isn't a bug in Chrome, or even a bug in Gmail. Gmail will not allow you to create an account that differs from an existing account only by a dot.
Project Member

Comment 2 by sheriffbot@chromium.org, Aug 6

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment