Issue metadata
Sign in to add a comment
|
Gmail sign in security breach.
Reported by
jacobdep...@gmail.com,
Aug 28
|
||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36 Steps to reproduce the problem: 1. Open network and attempt to sign in with incorrect pass. 2. Calculate the number difference and bring to the 5 power. 3. Use the numbers to calculate numerical and alphabetical values. What is the expected behavior? To not be able to exploit Gmail and other google services this way. What went wrong? Calculate(for instance): 3a 4c d7. You would bring to the 5th power and all the letters will be filled in by their alphabetical value. If it is above the alphabet, go 0, 1, 2, 3, etc. Did this work before? N/A Chrome version: 68.0.3440.106 Channel: stable OS Version: 10.0 Flash Version: 30.0.0.154 I am a security analytic and I used this on my own account to test the security of my account on Google.
,
Dec 5
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by kenrb@chromium.org
, Aug 28