• qaz@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    ·
    10 hours ago

    Here’s a POC of the exploit in action:

    This video has been removed for violating the YouTube TOS

    • pHr34kY@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      9 hours ago

      Sharing a video about a Google security vulnerability on Google’s own platform. What would you expect?

      • qaz@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        ·
        8 hours ago

        They did disclose it to Google before, and got a bounty but it seems the moderators from YouTube didn’t get the memo

  • flames5123@lemmy.world
    link
    fedilink
    English
    arrow-up
    21
    ·
    16 hours ago

    When FFXIV implemented better blocking tools this past summer, there was an option when blocking a single character to block the entire service account. This would be fine, but the implementation they went with is client side, and when you select that option, you get the service account ID. Which means that if you’re blocked by someone, you can’t made an alt character to stalk/harass them. But with third party tools, we can see this account ID. The stalker could just use a new account and find the person’s account ID that they were harassing and find any alt character they have in the game. They’re changing this soon as a third party tool popped up and is now able to do this, full source code leaked so there’s no shutting it down until the game devs change how it’s done.

    This sounds super similar, but the implementation that you had to do for google is crazy.

  • Dil@is.hardlywork.ing
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    edit-2
    16 hours ago

    This and some browsing of the public Facebook account will get you into most people’s accounts with minimal effort, social engineering is wild and made me lose interest in being a hacker growing up because it was too easy and made me uncomfortable. (I wanted to be mr robot so bad, I was delusional lol)

    • Maiq@lemy.lol
      link
      fedilink
      English
      arrow-up
      11
      ·
      15 hours ago

      Remember back in the day when you could get apple users emails through a simple number incrimination in i believe the app store website?

      The documentary The Hacker Wars highlighted the issue and if i remember weev went to jail for it. I probably need to rematch it again.

      Also if people are interested in that kind of documentary The Internet’s Own Boy is a heartbreakingly excellent story of what the US put Allen Schwartz through.

    • Dil@is.hardlywork.ing
      link
      fedilink
      English
      arrow-up
      2
      ·
      16 hours ago

      (This was when facebook contacts would/could get added to yahoo contacts or whatever? IDK I had 100s of emails in there)

  • TJA!@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    20
    arrow-down
    1
    ·
    22 hours ago

    So… Google Mail will not show me emails if their title is 2.5 million letters long? Pathetic