Google Docs users hit with sophisticated phishing attack

Discussion in 'malware problems & news' started by ronjor, May 3, 2017.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,123
    Location:
    Texas
  2. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,874
    Location:
    New York City
  3. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,909
    Location:
    Slovenia, EU
    https://www.forbes.com/sites/leemat...e-docs-phishing-attack-has-taken-a-weird-turn
     
  4. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,123
    Location:
    Texas
    Why OAuth Phishing Poses A New Threat to Users
     
  5. Abdallah

    Abdallah Registered Member

    Joined:
    Oct 28, 2013
    Posts:
    124
    Location:
    N/A
    There is someone on Twitter (maybe the same guy behind this "attack") claims that this was just a university student project!
     
  6. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    "Google was warned of Google Docs phishing technique 6 years ago

    The mass phishing scam that hit Google account holders this week has taken some bizarre twists and turns. The most shocking perhaps is that Google was warned of the possibility of such an attack six years ago but despite rewarding the security researcher who flagged the vulnerability, did not do enough to address it...

    Motherboard also said that, in 2012, security researcher Andre DeMarre had warned Google about the phishing technique, suggesting that the company address the issue by checking if the name of any given app matched the URL of the firm behind it. However, Google responded to DeMarre that they will not perform the URL validation. This decision was reportedly criticised by experts and DeMarre..."

    http://www.ibtimes.co.uk/google-was-warned-google-docs-phishing-technique-6-years-ago-1620115

    https://www.theregister.co.uk/2017/...nty_for_bug_behind_docs_drama_five_years_ago/
     
  7. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,123
    Location:
    Texas
    Google Takes Second Swing at OAuth Worm
     
  8. guest

    guest Guest

    Phishing Defense: Block OAuth Token Attacks
    But OAuth Attack Defense Remains Tricky, Warns FireEye's Douglas Bienstock
    June 21, 2018
    https://www.inforisktoday.com/phishing-defense-block-oauth-token-attacks-a-11117
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice