ProtonMail Reading Encrypted Data Logical Error

2020.02.19
tr Gaddar (TR) tr
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

Description : Due to this error, we can read the topics of the encrypted data and read some information. Author : Gaddar Team : SiyahBayrak PoC; - Create ProtonMail account. - Send post your mail. - Send a mail to an email address(ProtonMail) you have created from a different email address. - Now post readable. (Not Encrypted) - Log out ProtonMail account. - Reset password. - Accept steps. - Login your ProtonMail account after reset password. Authorities tell you that your old mail will be encrypted. - You can read post titles but you're cannot read post details. But this sometimes dangerous. Please look example :) Ex : https://ibb.co/RDWjFs0 My social accounts ; Instagram.com/pt.php Facebook.com/ptsec Twitter.com/ptguvenlik Youtube.com/c/gaddarsec My Teammates : DeadLy-Warrior - StabilBey - Diablo

References:

https://ibb.co/RDWjFs0


Vote for this issue:
55%
45%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top