[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAHL+=fXAMerz8pFgAu=81s6sKMg1fvYaSDSnXK393Bp=4wfswQ@mail.gmail.com>
Date: Tue, 27 Aug 2013 15:30:06 -0400
From: Jacob Morgan <jacob@...ldism.net>
To: full-disclosure@...ts.grok.org.uk
Subject: Google Docs Clickjacking / Information Disclosure
I reported this problem to Google in June but I did not get the usual reply
saying they were working on it, so I guess it isn't serious enough to be
fixed.
The problem is the page for requesting access to a private document. It
does not have any protection against being framed, so you can make a
private document, trick someone into clicking the button to request access
and get an email from Google Docs with their full name and email address.
PoC: http://buildism.net/files/GoogleDocsClickjacking2.html
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists