Author Topic: Massive attack underway using google docs  (Read 2938 times)

0 Members and 1 Guest are viewing this topic.

Offline Leslieann

  • * Elevated Elder
  • Thread Starter
  • Posts: 4519
Massive attack underway using google docs
« on: Wed, 03 May 2017, 19:41:22 »
This is hitting news sites quickly, because it's spreading like wildfire (one of my suppliers got hit by it) and many news sites have it wrong.
This is a new form of attack, anti-virus will not help and your operating system doesn't matter.

What it is, how it hits:
This attack is being carried out by email, it comes from someone who has you in their list of contacts and claims to be a shared Google document. It is not a shared document, it is an app trying to gain access to your docs.

What it does:
Clicking the link takes you to an actual Google page, the link is legit. The problem is, it is not taking you to a Google Document file shared with you, it takes you to the page that authorizes a program or person to access your Gmail, Docs, Drive and contacts and asks for access. If you click without thinking, it grants them access to everything.


Note that:
A. It won't be flagged as fake because it takes you to your actual Google account. This is how shared documents work, they simply reversed it.
B The attack CANNOT be carried out without you authorizing it.

How to protect yourself:
If you happened to click the link in email, but did not click authorize, you are safe, but following below will let you verify that and see what else has access to your documents.

How to fix it if you got hit or just want to verify you are safe:
If you did click the link, and clicked authorize, go into Gmail, then My Account (it's in the 9 dots on top left), then under "Sign In and Security", click "connected apps and sites", then "Manage Apps".  In this you will find a list of things authorized to access your Google files and should be in the order they were authorized, so the last one is most likely the one you need to kill and it should be labeled "Google Docs".
Novelkeys NK65AE w/62g Zilents/39g springs
More
62g Zilents/lubed/Novelkeys 39g springs, HK Gaming Thick PBT caps, Netdot Gen10 magnetic cable, pic
| Filco MJ2 L.E. Vortex Case, Jailhouse Blues, heavily customized
More
Vortex case squared up/blasted finish removed/custom feet/paint/winkey blockoff plate, HID Liberator, stainless steel universal plate, 3d printed adapters, Type C, Netdot Gen10 magnetic cable, foam sound dampened, HK Gaming Thick PBT caps (o-ringed), Cherry Jailhouse Blues w/lubed/clipped Cherry light springs, 40g actuation
| GMMK TKL
More
w/ Kailh Purple Pros/lubed/Novelkeys 39g springs, HK Gaming Thick PBT caps, Netdot Gen10 Magnetic cable
| PF65 3d printed 65% w/LCD and hot swap
More
Box Jades, Interchangeable trim, mini lcd, QMK, underglow, HK Gaming Thick PBT caps, O-rings, Netdot Gen10 magnetic cable, in progress link
| Magicforce 68
More
MF68 pcb, Outemu Blues, in progress
| YMDK75 Jail Housed Gateron Blues
More
J-spacers, YMDK Thick PBT, O-rings, SIP sockets
| KBT Race S L.E.
More
Ergo Clears, custom WASD caps
| Das Pro
More
Costar model with browns
| GH60
More
Cherry Blacks, custom 3d printed case
| Logitech Illumininated | IBM Model M (x2)
Definitive Omron Guide. | 3d printed Keyboard FAQ/Discussion

Offline hkf

  • Posts: 206
  • Location: Sydney, Australia
  • your #1 fan

Offline Leslieann

  • * Elevated Elder
  • Thread Starter
  • Posts: 4519
Re: Massive attack underway using google docs
« Reply #2 on: Wed, 03 May 2017, 21:02:17 »
Until the next one...

Still good idea to check what has access..
Novelkeys NK65AE w/62g Zilents/39g springs
More
62g Zilents/lubed/Novelkeys 39g springs, HK Gaming Thick PBT caps, Netdot Gen10 magnetic cable, pic
| Filco MJ2 L.E. Vortex Case, Jailhouse Blues, heavily customized
More
Vortex case squared up/blasted finish removed/custom feet/paint/winkey blockoff plate, HID Liberator, stainless steel universal plate, 3d printed adapters, Type C, Netdot Gen10 magnetic cable, foam sound dampened, HK Gaming Thick PBT caps (o-ringed), Cherry Jailhouse Blues w/lubed/clipped Cherry light springs, 40g actuation
| GMMK TKL
More
w/ Kailh Purple Pros/lubed/Novelkeys 39g springs, HK Gaming Thick PBT caps, Netdot Gen10 Magnetic cable
| PF65 3d printed 65% w/LCD and hot swap
More
Box Jades, Interchangeable trim, mini lcd, QMK, underglow, HK Gaming Thick PBT caps, O-rings, Netdot Gen10 magnetic cable, in progress link
| Magicforce 68
More
MF68 pcb, Outemu Blues, in progress
| YMDK75 Jail Housed Gateron Blues
More
J-spacers, YMDK Thick PBT, O-rings, SIP sockets
| KBT Race S L.E.
More
Ergo Clears, custom WASD caps
| Das Pro
More
Costar model with browns
| GH60
More
Cherry Blacks, custom 3d printed case
| Logitech Illumininated | IBM Model M (x2)
Definitive Omron Guide. | 3d printed Keyboard FAQ/Discussion

Offline rowdy

  • HHKB Hapster
  • * Erudite Elder
  • Posts: 21175
  • Location: melbourne.vic.au
  • Missed another sale.
Re: Massive attack underway using google docs
« Reply #3 on: Wed, 03 May 2017, 22:05:39 »
Thanks for posting this.

I'd kinds heard about it here and there, but as we don't use Google Docs I wasn't expecting to (and have not) receive any such email.

Still for those who don't get out much, you can't be warned too much about things like this.
"Because keyboards are accessories to PC makers, they focus on minimizing the manufacturing costs. But that’s incorrect. It’s in HHKB’s slogan, but when America’s cowboys were in the middle of a trip and their horse died, they would leave the horse there. But even if they were in the middle of a desert, they would take their saddle with them. The horse was a consumable good, but the saddle was an interface that their bodies had gotten used to. In the same vein, PCs are consumable goods, while keyboards are important interfaces." - Eiiti Wada

NEC APC-H4100E | Ducky DK9008 Shine MX blue LED red | Ducky DK9008 Shine MX blue LED green | Link 900243-08 | CM QFR MX black | KeyCool 87 white MX reds | HHKB 2 Pro | Model M 02-Mar-1993 | Model M 29-Nov-1995 | CM Trigger (broken) | CM QFS MX green | Ducky DK9087 Shine 3 TKL Yellow Edition MX black | Lexmark SSK 21-Apr-1994 | IBM SSK 13-Oct-1987 | CODE TKL MX clear | Model M 122 01-Jun-1988

Ị̸͚̯̲́ͤ̃͑̇̑ͯ̊̂͟ͅs̞͚̩͉̝̪̲͗͊ͪ̽̚̚ ̭̦͖͕̑́͌ͬͩ͟t̷̻͔̙̑͟h̹̠̼͋ͤ͋i̤̜̣̦̱̫͈͔̞ͭ͑ͥ̌̔s̬͔͎̍̈ͥͫ̐̾ͣ̔̇͘ͅ ̩̘̼͆̐̕e̞̰͓̲̺̎͐̏ͬ̓̅̾͠͝ͅv̶̰͕̱̞̥̍ͣ̄̕e͕͙͖̬̜͓͎̤̊ͭ͐͝ṇ̰͎̱̤̟̭ͫ͌̌͢͠ͅ ̳̥̦ͮ̐ͤ̎̊ͣ͡͡n̤̜̙̺̪̒͜e̶̻̦̿ͮ̂̀c̝̘̝͖̠̖͐ͨͪ̈̐͌ͩ̀e̷̥͇̋ͦs̢̡̤ͤͤͯ͜s͈̠̉̑͘a̱͕̗͖̳̥̺ͬͦͧ͆̌̑͡r̶̟̖̈͘ỷ̮̦̩͙͔ͫ̾ͬ̔ͬͮ̌?̵̘͇͔͙ͥͪ͞ͅ

Offline Joey Quinn

  • Posts: 4543
  • Location: Houghton
  • "..."
Re: Massive attack underway using google docs
« Reply #4 on: Wed, 03 May 2017, 22:47:20 »
The scam hit my school, everyone with an MTU email account got a few. I was actually talking to my advisor about it earlier today  :))
People in the 1980s, in general, were clearly just better than we are now in every measurable way.

The dumber the reason the more it must be done

Offline Leslieann

  • * Elevated Elder
  • Thread Starter
  • Posts: 4519
Re: Massive attack underway using google docs
« Reply #5 on: Thu, 04 May 2017, 01:54:07 »
Normally I wouldn't warn a bunch of geeks, but this was clever and VERY fast moving.

It's been years since we had one move this fast and to be used through a legitimate system was really slick. In a way, I have to admire the person who came up with it.
Novelkeys NK65AE w/62g Zilents/39g springs
More
62g Zilents/lubed/Novelkeys 39g springs, HK Gaming Thick PBT caps, Netdot Gen10 magnetic cable, pic
| Filco MJ2 L.E. Vortex Case, Jailhouse Blues, heavily customized
More
Vortex case squared up/blasted finish removed/custom feet/paint/winkey blockoff plate, HID Liberator, stainless steel universal plate, 3d printed adapters, Type C, Netdot Gen10 magnetic cable, foam sound dampened, HK Gaming Thick PBT caps (o-ringed), Cherry Jailhouse Blues w/lubed/clipped Cherry light springs, 40g actuation
| GMMK TKL
More
w/ Kailh Purple Pros/lubed/Novelkeys 39g springs, HK Gaming Thick PBT caps, Netdot Gen10 Magnetic cable
| PF65 3d printed 65% w/LCD and hot swap
More
Box Jades, Interchangeable trim, mini lcd, QMK, underglow, HK Gaming Thick PBT caps, O-rings, Netdot Gen10 magnetic cable, in progress link
| Magicforce 68
More
MF68 pcb, Outemu Blues, in progress
| YMDK75 Jail Housed Gateron Blues
More
J-spacers, YMDK Thick PBT, O-rings, SIP sockets
| KBT Race S L.E.
More
Ergo Clears, custom WASD caps
| Das Pro
More
Costar model with browns
| GH60
More
Cherry Blacks, custom 3d printed case
| Logitech Illumininated | IBM Model M (x2)
Definitive Omron Guide. | 3d printed Keyboard FAQ/Discussion

Offline SBJ

  • Posts: 1191
  • Location: Denmark / The city.
  • Tactile pls
Re: Massive attack underway using google docs
« Reply #6 on: Thu, 04 May 2017, 02:26:23 »
Thanks for posting this.
Usually I wouldn't worry too much but we use google docs heavily at work so I've been extra careful with all the shared docs lately.

Offline Sniping

  • Posts: 861
  • Location: California
Re: Massive attack underway using google docs
« Reply #7 on: Sun, 07 May 2017, 23:13:04 »
I saw this spread around really quickly as well. It's kinda unsettling because most people on the forum are well aware of what type of phishing scheme this is, but in the heat of the moment it can be really hard to spot. I fell for a similar thing just last year where I opened an email that prompted for my paypal info in a similar sneaky manner. Fortunately, I entered the wrong password LOL so I was fine, but it shook me up a little because I was completely unaware of what I was falling for until it was (almost) too late.

Offline SBJ

  • Posts: 1191
  • Location: Denmark / The city.
  • Tactile pls
Re: Massive attack underway using google docs
« Reply #8 on: Mon, 08 May 2017, 00:48:19 »
I saw this spread around really quickly as well. It's kinda unsettling because most people on the forum are well aware of what type of phishing scheme this is, but in the heat of the moment it can be really hard to spot. I fell for a similar thing just last year where I opened an email that prompted for my paypal info in a similar sneaky manner. Fortunately, I entered the wrong password LOL so I was fine, but it shook me up a little because I was completely unaware of what I was falling for until it was (almost) too late.
Some of them are painfully obvious and others are really sneaky.
Around tax season here in DK there are usually some phishing emails floating around, my mother almost fell for it once.

Offline Leslieann

  • * Elevated Elder
  • Thread Starter
  • Posts: 4519
Re: Massive attack underway using google docs
« Reply #9 on: Mon, 08 May 2017, 01:38:29 »
The thing with this was it was legit, just reversed on you.
So if you were not paying close attention ("why is it asking me permission) and just check the URL and such, it was 100% legitimate.


Really annoying, Google paid a hacker for finding this hole a long time ago and just never fixed it. Now someone uses it, and they fix it in5 minutes.  If it took that little time, why did it take so long to fix and why was it worth a bounty?
Novelkeys NK65AE w/62g Zilents/39g springs
More
62g Zilents/lubed/Novelkeys 39g springs, HK Gaming Thick PBT caps, Netdot Gen10 magnetic cable, pic
| Filco MJ2 L.E. Vortex Case, Jailhouse Blues, heavily customized
More
Vortex case squared up/blasted finish removed/custom feet/paint/winkey blockoff plate, HID Liberator, stainless steel universal plate, 3d printed adapters, Type C, Netdot Gen10 magnetic cable, foam sound dampened, HK Gaming Thick PBT caps (o-ringed), Cherry Jailhouse Blues w/lubed/clipped Cherry light springs, 40g actuation
| GMMK TKL
More
w/ Kailh Purple Pros/lubed/Novelkeys 39g springs, HK Gaming Thick PBT caps, Netdot Gen10 Magnetic cable
| PF65 3d printed 65% w/LCD and hot swap
More
Box Jades, Interchangeable trim, mini lcd, QMK, underglow, HK Gaming Thick PBT caps, O-rings, Netdot Gen10 magnetic cable, in progress link
| Magicforce 68
More
MF68 pcb, Outemu Blues, in progress
| YMDK75 Jail Housed Gateron Blues
More
J-spacers, YMDK Thick PBT, O-rings, SIP sockets
| KBT Race S L.E.
More
Ergo Clears, custom WASD caps
| Das Pro
More
Costar model with browns
| GH60
More
Cherry Blacks, custom 3d printed case
| Logitech Illumininated | IBM Model M (x2)
Definitive Omron Guide. | 3d printed Keyboard FAQ/Discussion

Offline tp4tissue

  • * Destiny Supporter
  • Posts: 13568
  • Location: Official Geekhack Public Defender..
  • OmniExpert of: Rice, Top-Ramen, Ergodox, n Females
Re: Massive attack underway using google docs
« Reply #10 on: Mon, 08 May 2017, 08:02:28 »
The thing with this was it was legit, just reversed on you.
So if you were not paying close attention ("why is it asking me permission) and just check the URL and such, it was 100% legitimate.


Really annoying, Google paid a hacker for finding this hole a long time ago and just never fixed it. Now someone uses it, and they fix it in5 minutes.  If it took that little time, why did it take so long to fix and why was it worth a bounty?



Obviously,  this was so they can use the hole themselves to target anti-google outlets..