TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

New Malware Stays Logged into Stolen Google Accounts After Password Reset

6 点作者 safaa1993超过 1 年前

1 comment

armchairhacker超过 1 年前
&gt; Last October 2023, a user known by the pseudonym PRISMA revealed on his Telegram channel that he had managed to restore expired Google authentication cookies. This allowed him to access Gmail accounts, even if the user had changed the password, and generate new session cookies with which to continue entering them in an unauthorized manner.<p>&gt; Specifically, what they do is take advantage of an endpoint called MultiLogin from Google OAuth to log into user accounts without having to follow the authentication process. This was revealed in a publication on his official blog<p>The blog (<a href="https:&#x2F;&#x2F;www.cloudsek.com&#x2F;blog&#x2F;compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking" rel="nofollow">https:&#x2F;&#x2F;www.cloudsek.com&#x2F;blog&#x2F;compromising-google-accounts-m...</a>) goes into a lot more detail. In particular is this point:<p>&gt; While we await a comprehensive solution from Google, users can take immediate action to safeguard against this exploit. If you suspect your account may have been compromised, or as a general precaution, sign out of all browser profiles to invalidate the current session tokens. Following this, reset your password and sign back in to generate new tokens. This is especially crucial for users whose tokens and GAIA IDs might have been exfiltrated. Resetting your password effectively disrupts unauthorized access by invalidating the old tokens which the infostealers rely on, thus providing a crucial barrier to the continuation of their exploit.<p>I&#x27;m confused on how and why the exploit and &quot;safeguard&quot; (not even sure it stops the exploit) works. When you reset your password, intuitively the server should invalidate all your session cookies, automatically logging you out of every device in the process. Is Google not doing that?