• Home
  • Contact

NARESH LAMGADE

ProtonMail Vulnerability : Bypassing Invitation

authorNaresh LamGade
29th September, 2015
bug

Featured Posts

  • TryHackMe : SQLMAP Writeup
    TryHackMe : SQLMAP Writeup
    16th May, 2021
  • Mega.nz Vulnerability: Payment Bypass on Mega Business
    Mega.nz Vulnerability: Payment Bypass on Mega Bus…
    5th June, 2020
  • Dynamic Execution : ASP.NET with Bootstrap
    Dynamic Execution : ASP.NET with Bootstrap
    28th April, 2017

Categories

blog bug bugs security Tech Tips & Trick TryHackMe tutorial Uncategorized

Naresh LamGade

authorNaresh LamGade
29th September, 2015
bug

ProtonMail is a secure encrypted email provider, which runs a “zero access” PGP mail service based in Switzerland. (Read More)

Since, ProtonMail doesn’t allow direct signup and they only accept the user through the invitation.
I had also signed up for ProtonMail to see the UI and all the things & go their invitation. I checked for some vulnerabilities and couldn’t find anything from the inside. Then I suddenly went through the invitation link which I was registered.

The first thing I notice was that INVITATION LINK never get expired.

Here’s mine : https://protonmail.ch/pre-invite/lamgade/37e81f840d77ca25de42191c2ddfe044

So, I thought of registering the new account again but still I was unable to registered as the username : lamgade was already registered then.

I went to the source code and found there was a field :

< input id=”username” tabindex=”1″ name=”UserName” readonly=”readonly” required=”” type=”text” value=”lamgade” placeholder=”Username” />

So, I just changed the value to any other username and made a request then I was able to register a new email account.

Then after finding this issue, I started making multiple emails for myself and for other friend.

And only , I reported the bug 😀 to the ProtonMail Security Team.

protonmail_beta_1
Since, It was only a Beta Version of a ProtonMail so they didn’t release any bug bounty but they send me two Official ProtonMail T-Shirt which still haven’t yet shipped.

protonmail_t-shirt

I have even made a Video POC :

(Note : This issue was reported back in December, 2014 and has been patched now. I was busy with other stuff so I didn’t make it out at a time so  I am posting now. 🙂 )

Comments




Share

Twitter Facebook Google+



  • ProtonMail : Bypassing Invitation
  • protonmail bug
  • protonmail issue
  • protonmail security vulnerability
  • protonmail vulnerability

TryHackMe : SQLMAP Writeup
author Naresh LamGade 16th May, 2021
Mega.nz Vulnerability: Payment Bypass on Mega Business
author Naresh LamGade 5th June, 2020
Comments
Harvey Specter
Posted at 6:02 pm September 29, 2015
Pranav Hivarekar
Author

Good find ! 🙂 Keep it up !

Harvey Specter
Posted at 6:03 pm September 29, 2015
nareshlamgade
Author

Thanks bro 🙂 more issue still to come. 🙂

Harvey Specter
Posted at 4:56 am September 30, 2015
Atul Shedage
Author

Nice!

Leave a Reply
Cancel Reply

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

Navigation
  • Home
  • Contact
Copyright © Naresh LamGade. 2025 • All rights reserved.
Proudly published with WordPress.