Whats up YouTube its Safwan from TechCycle in this video am going to share you guys an
information which will help you in the cyber world about this am going to share you guys
a design flaw a design flaw from google that is for the google inbox the new modern customisable
inbox for your gmail account a design flaw for that google inbox which is a simple design
flaw but if it get into the right hands its a major issue for us
I found out about this
design flaw only in the morning from a post from xda developers I will leave the post
link in the description you can find the details in the written form from there and am making
the video based on that post so about this design flaw this design flaw is found out
by Eli Grey as security researcher on may 4th 2017 and he informed google about this
design flaw privately after about one year roughly one year and on march 16th 2018 he
made that design flaw public so now its public and I tested this right now and it is till
now unresolved so about this design flaw before knowing about this design flaw you need to
know what is mailto so if your ever browsing a web page there will be a link when you click
that link it will directly redirect you to gmail inbox gmail compose menu so then the
to address subject will be filled automatically basically it is used by support pages like
paypal all those support pages so when you click that link it will redirect you to gmail
and gmail compose menu with all these details pre-filled so this mailto for google inbox
there is loophole on that so when you click a link which is redirected to this google inbox
am saying google inbox because this design flaw is not for gmail outlook any sort of
that this design flaw is only for google inbox the new google inbox its not new but now only
it is popular so about this design flaw when you click a link which redirect you to the
compose menu of inbox the pre-filled information will show you guys support@paypal.com that
is to address will be support@paypal.com but when you fill all the details like subject
all the compose menu all the subject all the details of the composing that is what is your
problem to the paypal and when you send this email will not be sent to support@paypal.com
it will be sent to any other address that is the address created by this mailto link
generator so to understand or to make it more clear I will share you guys with a example
from the xda developers web page they are giving a mailto link with address support@paypal.com
and it is not going to send that to support@paypal.com it will be sent to the scammers which is not
a official this is only for testing purpose so when I click this mailto link its redirecting
me to the compose menu of google inbox on the google inbox you can see that its saying
support@paypal.com when I when I open that to address its not showing any more details
and I filled this subject with testing and compose menu with testing and am going to
send that message after sending in the sent menu am seeing the message as being sent and
am going to open the gmail on the gmail when I went to sent items and when I expanded the
to address its showing me that the name is just support@paypal.com but the original email
id the email id that I used to the email id that I sent this testing testing message is
this scammers so that is the design flaw in this google inbox and google is not ready
to fix this after an year so we need to more careful while choosing this google inbox right
now to protect yourself from this design flaw you can either use gmail outlook or any other
emailing system or emailing webpage I prefer gmail but if you want to still use this google
inbox just make sure when you click this mailto just make sure that the redirecting link in
this address bar is just the support link your sending the mail not there is no other
name like in this scammers.
something like that make sure that in the xda post you can find the perfect example
for the importance of fix for this design flaw or the issue of this design flaw that
is in that screenshot you can find a person sending a message sending a email to paypal
support by helping him to add a credit card number to the account so thats the main issue
of that if your sending your credit card details to support@paypal.com which is not sending
that to support@paypal.com but its sending that to someone else an hacker who is very
much into hacking so its going to be a great issue for us also this design flaw can be
used by hackers for exploiting your private details that is your privacy will be in danger
if your sending some support@paypal.com or something other support page or any other
page or mailto link about your personal details for the purpose of that email purpose of that
email that is if your sending paypal for details regarding your bank account balance and every
sort of things if you sent that to any hacker he can use that to exploit you so make sure
that your safe from design flaw or security flaw you can say that but design flaw is good
its not any vulnerability its something design flaw that is in xda post they updated that
post to be in design flaw so thats all about this video guys make sure your safe in the
cyber world always protect your private details check whether the address is redirecting to
the same address and be safe thanks for watching talk to you in next one and don't forget to
subscribe
Không có nhận xét nào:
Đăng nhận xét