Stored XSS in GMail for iOS
roy-castillo.blogspot.ru
roy-castillo.blogspot.ru
It also shows that there isn't a blame culture inside the team, otherwise people would be looking to cover up this kind of report.
<plug> The flaw was discovered automatically by one of the tests in a web application which I authored: https://emailprivacytester.com/ </plug>
EDIT: I've added a new test to the tester, for hiding a script payload in the onerror attribute of an img tag in the From header of emails.
Does anyone have any recommended resources ? TIA !
https://www.owasp.org/index.php/Top_10_2013-Top_10
http://www.nsa.gov/ia/_files/support/I733-034R-2007.pdf
http://www.nsa.gov/ia/_files/factsheets/TSA-13-1019-FS.pdf
https://code.google.com/p/skipfish/
http://google-gruyere.appspot.com/
http://www.google.com/about/appsecurity/tools/
http://googleonlinesecurity.blogspot.com/2010/11/rewarding-w...
http://www-01.ibm.com/software/tivoli/governance/security/ap...
http://www-01.ibm.com/software/tivoli/products/security-netw...
http://msdn.microsoft.com/en-us/library/ff649874.aspx
http://msdn.microsoft.com/en-us/library/ff649461.aspx
Source: typing "web application security" into google.com
You could probably also search for "Hacking Forums" or something similar and find lots of black hat resources.
It covers the process of a web application test and explains 90% of the vulnerabilities you'll find in web apps and how to test for them.
1) He is using Windows and is not using Burp or ZAP proxy for modifying http requests. With Windows you can't use <>"= in a filename.
2) Gmail is handling emails from Google Analytics a bit different. (I don't think so)