Saturday, 15 May 2010

GMAIL GIVES WAY TO HACKERS

All security measures will have loophole in it, to prove this we will see a case here.
Google had created many user application and gadgets for the benefit of user but these applications and features also turn back as a security threats. One such is 'Google hack'
witch is nothing but using the popular search engine to get the unsecured cam in the internet by using the search codes like inurl:view/indexFrame.shtml and more queries like this we can also see a unprotected admin page, password file in a FTP server and many more. In my next topic we will see how this will lead to hack a router. Similarly now I came across with another security hole in a gadget in a GMAIL.

If you login to your mail, after loading the page at the bottom you will find few details in small font like you see in this picture below,





.
You will find a detail about your total capacity of the mail and the used space, next to that you will find a statement "LAST ACCOUNT ACTIVITY 1 HOUR IP: 111.111.111.111 WHICH IS YOUR PUBLIC IP WHICH YOU USED LAST TIME TO LOGIN and next to that you will find a link DETAIL here you can see the last 5 login sessions and ip address used and the type of service you have used to open the mail.
This service is given by gmail to know is some one had accessed your account or if you have opened the same account in any other device like mobile or in different browser we can close those sessions. Just imagine if some one shoulder sniff this detail or ur account is been compromised by a hacker he can come to know about the IP address if the last five session has been from same ip he will come to a conclusion that this ip should be your personal system's IP and if that user unfortunately uses the same username and password for his orkut he can sign in and he can get the personal information from his profile and use that for getting through your personal computer, most user use ther name or date of birth or even same password of the mail to their PC's login details, so this will be very easy for the hacker to get into the system remotely.

If the hacker come to know your private ip address he can scan your system for the vulnerability and compromise your system.

So be sure you are alone when you check your mail for at least still Google come to know about this threat.

No comments:

Post a Comment

Conformio-Online Compliance Tool Multiple Vulnerabilities

# Exploit Title: Conformio-Online Compliance Tool Multiple Vulnerabilities. # Discovered Date: 16/11/2017 # Exploit Author: Ramikan # Websi...