lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 16 May 2008 00:46:43 +0100
From: n3td3v <xploitable@...il.com>
To: full-disclosure@...ts.grok.org.uk, security@...gle.com
Subject: Forwarding message vulnerability on Google Groups

If joebloggs@...gle.com is banned from a Google Group and
xploitable@...il.com is registered with that group,
joebloggs@...gle.com can subscribe to a mailing list such as
Full-Disclosure and start forwarding all messages xploitable@...il.com
sends to that mailing list if xploitable@...il.com is registered to
it, and directly post them to the Google Group joebloggs@...gle.com is
banned from.

This is probably done by the banned joebloggs@...gle.com setting up a
filter on Gmail Settings > Filter > Matches:
from:(xploitable@...il.com)
Do this: Forward to (n3td3v@...glegroups.com).

Severity of this issue is obviously critical and you should switch the
victim's registered (xploitable@...il.com) e-mail address on a Google
Group to "moderate" as a work around, until Google Groups fixes this
vulnerability.

Google Inc. (GOOG) was notified simultaneously as this security
advisory was published to the wild.

http://finance.google.com/finance?q=NASDAQ:GOOG/

http://groups.google.com/

http://google.com/

All the best,

n3td3v

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ