The Gmail “Zombie Token” Google Refused to Kill
中文摘要
研究人员发现并报告了Gmail“以其他地址发送邮件”功能中的持久授权绕过漏洞,该漏洞现已被谷歌修复。
English Summary
A researcher discovered a persistent authorization bypass vulnerability in Gmail's "Send Mail As" feature, which Google has since fixed.
原文节选
Here is how I found a persistent authorization bypass in Gmail’s ‘Send Mail As’ feature, documented it with video proof, and got it closed… Continue reading on OSINT Team »