View Single Post
Old 06-07-11, 19:34   #1
Ladybbird
 
Ladybbird's Avatar
 
Join Date: Feb 2011
Posts: 47,626
Thanks: 27,642
Thanked 14,458 Times in 10,262 Posts
Ladybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond reputeLadybbird has a reputation beyond repute

Awards Showcase
Best Admin Best Admin Gold Medal Gold Medal 
Total Awards: 8

WARNING - Google is Hacked! by Identity Thieves

Phishers have found a new use for Google Docs -- Stealing Your Identity

By Beta News





The free cloud applications, particularly Google spreadsheets, are gaining popularity as a phishing platform. I knew the Google Docs spreadsheet was good for something.

One of the main jobs of a phishing site in selling itself is to come from a trustworthy domain, and that's why Google Apps is so popular. Nobody is going to block *.google.com or even spreadsheets.google.com. So not only will some people be more inclined to believe that a phishing page is genuine, but it's less likely to be blocked by reputation systems. You even get to use HTTPS on your attack page, courtesy of Google.

Alex Eckelberry of (the Sunbelt Software guys who got bought by) GFI Software says they're seeing a lot of Google Docs phishing sites. Eckelberry gives one example, and there are others on his blog. He calls Google Spreadsheets a "playpen for phishers. We have found a very large number of phishing sites using Spreadsheets, especially for stealing credentials".

As Eckelberry says, the intended uses of Google Docs make it particularly vulnerable to this. It's perfect, for example, for teachers to gather information from students. So highly-targeted attacks, spear-phishing if you will, have a lot of potential. This is exacerbated by the opacity of the URLs which, in many cases, don't indicate anything about the identity of the author.

These attacks are apparently popular in Indonesia and used to steal credential for various games. Eckelberry cites Gemscool (an Indonesian gaming site) as a particular target, such as for the Point Blank (PB) and Lost Saga games. It's easy to find these attacks; try this Google search ("cheat lost saga jakarta site:google.com"). You should see a few, some of which have been found by Google and turned off.

It's just a month ago that I first saw a report of this technique. My conclusion then, as now, is that until Google cleans up its act Docs isn't a good place for such forms.
__________________
PUTIN TRUMP & Netanyahu Will Meet in HELL


..................SHARKS are Closing in on TRUMP..........................







TRUMP WARNS; 'There'll Be a Bloodbath If I Don't Get Elected'..MAGA - MyAssGotArrested...IT's COMING


PLEASE HELP THIS SITE..Click DONATE
& Thanks to ALL Members of ... 1..

THIS SITE IS MORE THAN JUST WAREZ...& TO STOP SPAM-IF YOU WANT TO POST, YOUR FIRST POST MUST BE IN WELCOMES
Ladybbird is online now  
The Following User Says Thank You to Ladybbird For This Useful Post:
FreaknDavid (08-07-11)