[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    [Full-disclosure] Google Docs Clickjacking / Information Disclosure
From:       Jacob Morgan <jacob () buildism ! net>
Date:       2013-08-27 19:30:06
Message-ID: CAHL+=fXAMerz8pFgAu=81s6sKMg1fvYaSDSnXK393Bp=4wfswQ () mail ! gmail ! com
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


I reported this problem to Google in June but I did not get the usual reply
saying they were working on it, so I guess it isn't serious enough to be
fixed.

The problem is the page for requesting access to a private document. It
does not have any protection against being framed, so you can make a
private document, trick someone into clicking the button to request access
and get an email from Google Docs with their full name and email address.

PoC: http://buildism.net/files/GoogleDocsClickjacking2.html

[Attachment #5 (text/html)]

<div dir="ltr">I reported this problem to Google in June but I did not get the usual reply \
saying they were working on it, so I guess it isn&#39;t serious enough to be \
fixed.<div><br></div><div>The problem is the page for requesting access to a private document. \
It does not have any protection against being framed, so you can make a private document, trick \
someone into clicking the button to request access and get an email from Google Docs with their \
full name and email address.</div> <div><br></div><div>PoC: <a \
href="http://buildism.net/files/GoogleDocsClickjacking2.html">http://buildism.net/files/GoogleDocsClickjacking2.html</a></div></div>




_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic