Gmail Glitch Offers Stealthy Trick for Phishing Attacks
#1
Quote:A strange glitch in Gmail can be exploited to place emails into a person’s “Sent” folder — even if that person never sent them.
Researchers who discovered the bug worry that it gives phishers and scammers another avenue to trick unsuspecting users into clicking on malicious links or opening rogue attachments.

The Gmail issue, discovered and outlined by software developer Tim Cotten this week, stems from the way that Gmail organizes its folders. It files an email into the Sent folder based on the address in the “from” field. So, if an attacker sends an email to a target, which has been specially crafted to also have that target’s email address in the “from” field, the mail will automatically go to the person’s inbox and Sent folder at the same time. This gives the false impression to the unwitting user that it was an email they themselves sent, said Cotten.

“So it appears that by structuring the from field to contain the recipient’s address along with other text, the GMail app reads the from field for filtering/inbox organization purposes and sorts the email as though it were sent from [the recipient], despite it clearly also having the originating mailbox as [another address],” he explained.

“The confusion being injected into the average user experience is an open door for malicious actors… Imagine, for instance, the scenario where a custom email could be crafted that mimics previous emails the sender has legitimately sent out containing various links,” said Cotten. “A person might, when wanting to remember what the links were, go back into their sent folder to find an example: disaster!”

Source: https://threatpost.com/gmail-glitch-offe...ks/139167/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, wwd
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
That weird CAPTCHA could be a malware t...
I hate captchas. One...akiratoriyama — 08:01
Audacity 3.0.5
Audacity 3.7.3 ...Kool — 15:17
That weird CAPTCHA could be a malware tr...
Follow the 'I'm no...harlan4096 — 12:26
RogueKiller 16.1.1
V16.1.1 03/11/2025...harlan4096 — 12:21
Hasleo Backup Suite 5.2
Hasleo Backup Suit...harlan4096 — 12:20

[-]
Birthdays
Today's Birthdays
avatar (38)chasRex
Upcoming Birthdays
avatar (43)gapedDow
avatar (37)snorydar
avatar (42)Hectorvot
avatar (50)knowhanPluts
avatar (38)Williamengiz
avatar (45)qaqapeti
avatar (43)battsourIonix
avatar (42)CedricSek
avatar (32)uteluxix
avatar (46)piafcflene
avatar (38)Matthewkah
avatar (37)Charlesfibre
avatar (37)francisnj3
avatar (42)artmaGoork

[-]
Online Staff
There are no staff members currently online.

>