ProtonMail Reading Encrypted Data Logical Error

2020.02.19
tr Gaddar (TR) tr
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

Description : Due to this error, we can read the topics of the encrypted data and read some information. Author : Gaddar Team : SiyahBayrak PoC; - Create ProtonMail account. - Send post your mail. - Send a mail to an email address(ProtonMail) you have created from a different email address. - Now post readable. (Not Encrypted) - Log out ProtonMail account. - Reset password. - Accept steps. - Login your ProtonMail account after reset password. Authorities tell you that your old mail will be encrypted. - You can read post titles but you're cannot read post details. But this sometimes dangerous. Please look example :) Ex : https://ibb.co/RDWjFs0 My social accounts ; Instagram.com/pt.php Facebook.com/ptsec Twitter.com/ptguvenlik Youtube.com/c/gaddarsec My Teammates : DeadLy-Warrior - StabilBey - Diablo

References:

https://ibb.co/RDWjFs0


Vote for this issue:
55%
45%

Comment it here.
Admin | Date: 2020-02-20 07:16 CET+1
Proton has bug bounty program. Did you reported it or fuck money?
Gaddar | Date: 2020-02-20 18:07 CET+1
We have money :) We don't need money.

Copyright 2025, cxsecurity.com

 

Back to Top