New issue
Advanced search Search tips

Issue 878361 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 28
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Gmail sign in security breach.

Reported by jacobdep...@gmail.com, Aug 28

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36

Steps to reproduce the problem:
1. Open network and attempt to sign in with incorrect pass.
2. Calculate the number difference and bring to the 5 power.
3. Use the numbers to calculate numerical and alphabetical values.

What is the expected behavior?
To not be able to exploit Gmail and other google services this way.

What went wrong?
Calculate(for instance): 3a 4c d7. You would bring to the 5th power and all the letters will be filled in by their alphabetical value. If it is above the alphabet, go 0, 1, 2, 3, etc.

Did this work before? N/A 

Chrome version: 68.0.3440.106  Channel: stable
OS Version: 10.0
Flash Version: 30.0.0.154

I am a security analytic and I used this on my own account to test the security of my account on Google.
 
Status: WontFix (was: Unconfirmed)
This tracker is for bugs in the Chrome browser. Problems with Google services should be submitted to the appropriate form (https://goo.gl/vulnz).
Project Member

Comment 2 by sheriffbot@chromium.org, Dec 5

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment