Gmail Account Hijacking Vulnerability
blog.securityfuse.com
blog.securityfuse.com
Either way, it isn't a hijack, you can just send email from the "hijacked" account through Google's servers, you can't receive email sent to the account.
[1] Yes, you have SPF and DMARC to contend with.
$ telnet localhost 25
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.
220 localhost.localdomain ESMTP
EHLO jlgaddis
250-localhost.localdomain
250-PIPELINING
250-SIZE 26214400
250-ETRN
250-STARTTLS
250-ENHANCEDSTATUSCODES
250-8BITMIME
250 DSN
MAIL FROM:<president@whitehouse.gov>
250 2.1.0 Ok
RCPT TO:<willvarfar@foo.bar.baz>
250 2.1.5 Ok
DATA
354 End data with <CR><LF>.<CR><LF>
From: President Barack Obama <president@whitehouse.gov>
To: willvarfar <willvarfar@foo.bar.baz>
Subject: LOLOL
This is an account hijack!
-BO
.
250 2.0.0 Ok: queued as 6AE031F5FE
QUIT
221 2.0.0 Bye
Connection closed by foreign host.
$You can use S/MIME as well, which has its own tradeoffs like all PKI but also somewhat more widespread and mildly more seamless support. But your basic, unless the e-mail is cryptographically signed in some manner there's no significant authentication for email. If cryptographic signing was more widespread then issues with spam, phishing/spearphishing, etc could be significantly reduced simply by virtue of elimination of spoofing. That day does not seem likely to come any time in the foreseeable future however, given that if anything end-to-end cryptography in email (be it for signing or encryption) seems to be going backwards, not forwards. It'll remain an irritating situation for a long time to come.
1) Email addresses added to the 'send from' list in Gmail are used to send emails with an alternative From: address, but they always contain a correct envelope-from header, so the emails will typically show up as 'Google (sent by: SuperHacker@gmail.com)', or something along those lines.
2) gmail.com doesn't have a forced-fail SPF record, so one could just send emails From: google@gmail.com using /any/ mail server, as long as the receiving mail server doesn't interpret softfail as fail -- and it shouldn't.
An unknown computer is still showing up as gaining access to my google account AFTER I have done all the typical sanitation events to my google account: changed password, disconnected all apps and services, and using 2-Step authentication (even only using the Authentication, not SMS).
When my account was compromised ~10 days ago, the first event in the attack was some service/app being connected to my gmail account. I regretfully did not screen shot the event (google only shows the last 10 login-events on the account).
I suspect some devious 3rd party app was installed/connected to my google account and is still by by-passing all of the 2-step authentication, and "disconnect all account" actions I have taken.
UPDATE: Here is URL/info where unknown computer is showing up: https://security.google.com/settings/u/0/security/activity
Any ideas? How the hell does one contact google on this?
Presumably the researcher expended a lot of effort probing gmail and was that time not worth a paltry reward?
vulnerabilities should be better rewarded.
The reason bug bounties exist is to reward hackers for reporting severe and/or difficult-to-find security issues, so that they don't publish it before it's fixed and so the company gets good PR.
In this case, the bug was clearly not that severe, and thus Google presumably decided it was not worth it for them to issue a reward. There is no right to compensation here, nor should somebody think they will definitely be paid if they do a company's work for them.
Well of course, but my reading of it is still that it's a damn shame he's getting nothing. Just because someone has no right to something doesn't necessarily mean they shouldn't get something.