Bitcoin Forum
December 11, 2024, 12:44:53 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: A hack to steal steal your Gmail password?  (Read 1769 times)
Eadeqa (OP)
Hero Member
*****
Offline Offline

Activity: 644
Merit: 500


View Profile
January 17, 2014, 12:56:59 PM
 #1

A few days ago (luckily) I read a PDF document that described a vulnerability in several password managers (like 1Passwprd, lastpass) that when they see say  "google.com" domain they will autofill gmail's password field and user name  (even if the fields are hidden on page) and when the user clicks on "continue"  or "vote" (if it was a poll  on the psge) the  passwords are sent to the hacker.

So today on twitter I saw this guy  

https://twitter.com/CoinMKTCap

giving a link to this page hosted on google.com

(be careful before clicking anything on the page)

https://docs.google.com/forms/d/1IZf5cBivam_93zENT_arFFuvWDidHGjWxoTMVmFSoWg/viewform

Now why on earth would this be on docs.google.com if this is anything legitimate? Why not on your own site?

Right click and "view source" and I do see things like on the page:

^(focus|focusin|submit)$/i,r=/^(input|textarea)$/i,s=/^password$/i,l=!!("placeholder"in x);l|

If this page steals gmails passwords (and I think most likely it does), I would have fallen for this  -- for sure --had I not read PDF that describes the hack just a few days before

https://www.isecpartners.com/media/106983/password_managers_nov13.pdf
  





Nomi, Shan, Adnan, Noshi, Nxt, Adn Khn
NXT-GZYP-FMRT-FQ9K-3YQGS
https://github.com/Lafihh/encryptiontest
MPOE-PR
Hero Member
*****
Offline Offline

Activity: 756
Merit: 522



View Profile
January 17, 2014, 03:59:05 PM
 #2

Protip: don't use password managers.

Please move this thread to scam accusations or somesuch; it doesn't belong in securities (there's a link lower right).

My Credentials  | THE BTC Stock Exchange | I have my very own anthology! | Use bitcointa.lk, it's like this one but better.
thecoinjournal
Hero Member
*****
Offline Offline

Activity: 490
Merit: 500



View Profile WWW
January 18, 2014, 02:51:17 AM
 #3

Double steal?

dexX7
Legendary
*
Offline Offline

Activity: 1106
Merit: 1026



View Profile WWW
January 19, 2014, 05:55:20 PM
 #4

Protip: don't use password managers.

Besides some potentially faulty features like auto fill-ins and such, what's your reasoning? And what solution do you suggest otherwise?

MPOE-PR
Hero Member
*****
Offline Offline

Activity: 756
Merit: 522



View Profile
January 21, 2014, 09:24:05 PM
 #5

Besides some potentially faulty features like auto fill-ins and such, what's your reasoning? And what solution do you suggest otherwise?

If it's in your head it's in your head. If it's stored by the password manager...well...then it's in there.

My Credentials  | THE BTC Stock Exchange | I have my very own anthology! | Use bitcointa.lk, it's like this one but better.
Haidang1796
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
January 22, 2014, 08:38:52 AM
 #6

wait what are the benefits to read other people email. unless that one is super important, I dont see any goods for the thieves to do that Huh

escrow.ms
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
January 22, 2014, 08:47:10 AM
 #7

wait what are the benefits to read other people email. unless that one is super important, I dont see any goods for the thieves to do that Huh

An email account can be used
to reset passwords of other accounts
to collect someome's personal information, pics and other important data,
to send spam messages.

There are many use of a hacked email account but it depends on who's the owner of that account.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!