{"id":1062103,"date":"2022-02-26T11:08:31","date_gmt":"2022-02-26T16:08:31","guid":{"rendered":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/uncategorized\/google-groups-unsubscribe-feature-abused-to-remove-members-without-consent-the-daily-swig\/"},"modified":"2022-02-26T11:08:31","modified_gmt":"2022-02-26T16:08:31","slug":"google-groups-unsubscribe-feature-abused-to-remove-members-without-consent-the-daily-swig","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/google\/google-groups-unsubscribe-feature-abused-to-remove-members-without-consent-the-daily-swig\/","title":{"rendered":"Google Groups unsubscribe feature abused to remove members without consent &#8211; The Daily Swig"},"content":{"rendered":"<p><p>    Emma Woollacott23 February 2022 at 11:52 UTC        Updated: 23 February 2022 at 11:57 UTC                                                        <\/p>\n<p>This could have destroyed the Google Payment system flow, security researcher tells The Daily Swig<\/p>\n<\/p>\n<p>A flaw in Google Groups has netted a security researcher $3,133 after he discovered that the unsubscribe feature could be abused to remove members without their consent.<\/p>\n<p>More than 20 years old, Google Groups allows people to set up discussion groups with a common mail ID for members. Using this service, members of the group can send a single email that will then be posted in the group chat.<\/p>\n<p>Members can automatically unsubscribe to the group by sending an email to, for example, <a href=\"mailto:test_groups_one+unsubscribe@googlegroups.com\">test_groups_one+unsubscribe@googlegroups.com<\/a>.<\/p>\n<p>DONT MISS Jaw-dropping Coinbase security bug allowed users to steal unlimited cryptocurrency<\/p>\n<p>However, Sriram Kesavan, founder and director of security at India-based TG Cyberlabs, discovered that it was possible to trick the system into removing Google Groups members at will, without their knowledge.<\/p>\n<p>His technique was to email the group and use the reply-to feature, common to most mailing services, so that any reply would be sent to the unsubscribe email address and the member automatically removed.<\/p>\n<p>Using auto-forwarding allowed Kesavan to make the group removal process invisible to the user concerned.<\/p>\n<p>Kesavan says he was able to use the technique to remove users from a Google Group he set up within his own company  and that Google itself uses the service as a Google Payment tracking system.<\/p>\n<p>Read more of the latest hacking news from around the world<\/p>\n<p>I could have literally removed Google employees on several official groups, even if I have no access to it, he tells The Daily Swig.<\/p>\n<p>This could have literally destroyed the Google Payment system flow, and could have caused delays on their internal payments.<\/p>\n<p>When Kesavan reported the issue to Google, it was at first rejected as intended behaviour. With permission, he then submitted a full write-up, which won him the a $3,133.70 reward.<\/p>\n<p>Initially the person who was attending to my report was not given sufficient information from my side to decide and finalize it as a valid security issue, he says.<\/p>\n<p>Later, when I decided to send a write-up which had all the information, they realized the impact of this issue and the team decided to patch this ASAP, so a quick and simple patch was applied in order to prevent users from exploiting it.<\/p>\n<p>A Google spokesperson said the company was unable to comment.<\/p>\n<p>YOU MIGHT ALSO LIKE AirTag clone bypassed Apples tracking-protection features, claims researcher<\/p>\n<p><!-- Auto Generated --><\/p>\n<p>See the article here: <\/p>\n<p><a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/portswigger.net\/daily-swig\/google-groups-unsubscribe-feature-abused-to-remove-members-without-consent\" title=\"Google Groups unsubscribe feature abused to remove members without consent - The Daily Swig\">Google Groups unsubscribe feature abused to remove members without consent - The Daily Swig<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Emma Woollacott23 February 2022 at 11:52 UTC Updated: 23 February 2022 at 11:57 UTC This could have destroyed the Google Payment system flow, security researcher tells The Daily Swig A flaw in Google Groups has netted a security researcher $3,133 after he discovered that the unsubscribe feature could be abused to remove members without their consent.  <a href=\"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/google\/google-groups-unsubscribe-feature-abused-to-remove-members-without-consent-the-daily-swig\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[345634],"tags":[],"class_list":["post-1062103","post","type-post","status-publish","format-standard","hentry","category-google"],"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/1062103"}],"collection":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/comments?post=1062103"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/posts\/1062103\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/media?parent=1062103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/categories?post=1062103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/prometheism-transhumanism-posthumanism\/wp-json\/wp\/v2\/tags?post=1062103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}