Torrent Invites! Buy, Trade, Sell Or Find Free Invites, For EVERY Private Tracker! HDBits.org, BTN, PTP, MTV, Empornium, Orpheus, Bibliotik, RED, IPT, TL, PHD etc!



Results 1 to 2 of 2
Like Tree1Likes
  • 1 Post By whiteLight

Thread: Hacker Finds a Simple Way to Bypass Google Password Alert

  1. #1
    It's Alright,You Heard?
    whiteLight's Avatar
    Reputation Points
    214616
    Reputation Power
    100
    Join Date
    Aug 2014
    Posts
    9,269
    Time Online
    462 d 3 h 45 m
    Avg. Time Online
    3 h 7 m
    Mentioned
    2378 Post(s)
    Quoted
    807 Post(s)
    Liked
    12475 times
    Feedbacks
    440 (100%)

    Hacker Finds a Simple Way to Bypass Google Password Alert

    Less than 24 hours after Google launched the new Phishing alert extension Password Alert, a security researcher was able to bypass the feature using deadly simple exploits.

    On Wednesday, the search engine giant launched a new Password Alert Chrome extension to alert its users whenever they accidentally enter their Google password on a carefully crafted phishing website that aimed at hijacking users’ account.

    However, security expert Paul Moore easily circumvented the technology using just seven lines of simple JavaScript code that kills phishing alerts as soon as they started to appear, defeating Google’s new Password Alert extension.


    Google shortly fixed the issue and released a new update to Password Alert extension that blocked the Moore’s exploit. However, Moore discovered another way to block the new version of Password Alert, as well.

    The first proof of concept exploit by Moore relied on a JavaScript that looks for instances of warning screen every five milliseconds and simply removes anything it detects. Generally, the warning screen is still there, but the exploit prevented the user from ever seeing it.

    Moore posted the proof-of-concept JavaScript exploit yesterday, explaining that Google’s Password Alert can be bypassed by anyone using just seven lines of code.

    Here’s the Kicker:

    However, Google assured its users that the company has now fixed the issue, releasing Password Alert version 1.4. "To update quickly, go to

    Chrome://extensions/ , enable developer mode, click update extensions now," Google engineer Drew Hintz said.

    But Moore didn’t want to stop here. He began analyzing the code for the extension more closely and figured out another way to bypass Password Alert, effectively killing phishing alerts as soon as they generated.


    Now, let’s see how much time the search engine giant would take to fix this issue in its all new Password Alert Chrome Extension.

    The technology was just launched by Google on Wednesday, so you can expect some flaws at its early stage.

    Password Alert extension has been installed by nearly 30,000 Chrome users, who are advised to update version 1.4, the latest version available at the moment, to fix the first issue.

    In order to fix another problem, you may have to wait until Google releases the next update. Till then, you are advised to turn on two-factor authentication and use a good password manager to protect yourself against phishing attacks.
    BoilerGuru likes this.

  2. #2
    Wanderer Mokoshotar's Avatar
    Reputation Points
    487
    Reputation Power
    38
    Join Date
    May 2015
    Posts
    136
    Time Online
    11 d 9 h 25 m
    Avg. Time Online
    5 m
    Mentioned
    44 Post(s)
    Quoted
    19 Post(s)
    Liked
    57 times
    Feedbacks
    5 (100%)
    Relying on them would only bring trouble. Its time to switch to a new and less-known email provider.


Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •