3 ms·
No, the screen w/ "Google stopped this sign in attempt" is not from Google. Presumably the "Change Password" link pointed to a server controlled by the phisher
by ebcode 10y ago
No, the screen w/ "Google stopped this sign in attempt" is not from Google. Presumably the "Change Password" link pointed to a server controlled by the phishers.
- acqq 10y agoI think you don't know what Google does and make an empty claim, unsupported by the screens displayed. They actually have such kind of protections, I've seen them. Why would the phishers inform the victim that they got his password? It's against their goals. Edit: Fascinatingly, the google.com/amp does the redirection, but the google.com is contacted first. Why would google.com do this? Ah, yes... the Google validated AMP cache. Nice. Edit2: Dude in the reply to this, the fascinating thing is, the google.com is actually contacted from that address first. Mind blown. The phishing using the actual, real google.com. Really, really, nice. That is for me the most fascinating detail from this whole story. It is actually the real www.google.com who made that thing possible. Wow.
- ebcode 10y agoDude. Look at the caption underneath those screenshots. They say, "A screenshot of the phishing email received by ..." The fact that Google actually sends out emails that look like that is what makes the phishing attack so effective. The email looks like it is from Google, and therefore trustworthy. As to why the phishers would inform him that they got his password? The reason is that at the time they sent the phishing email, they didn't actually have his password, and wanted him to click on a link that they controlled so he would give them his password. I'm trying to get through to you. Please tell me it's working.
- andreasley 10y agoThe open redirect on google.com has been known for a while: [1] Google's official policy regarding open redirectors: "Our take on this is that tooltips are not a reliable security indicator, and can be tampered with in many ways; so, we invest in technologies to detect and alert users about phishing and abuse, but we generally hold that a small number of properly monitored redirectors offers fairly clear benefits and poses very little practical risk." [2] [1] http://seclists.org/bugtraq/2016/Apr/70 http://seclists.org/bugtraq/2016/Apr/70 [2] https://sites.google.com/site/bughunteruniversity/nonvuln/open-redirect https://sites.google.com/site/bughunteruniversity/nonvuln/op...
- acqq 10y ago> "tooltips are not a reliable security indicator" Translation: "we don't look at that sh.t" > "poses very little practical risk." I'm sure Powell, Podesta and a big part of the world now clearly agree with them. /s Everybody knew t.co/sh.t is somewhere else. www.google.com/whatever/without/query wasn't. Fracking up the established expectations. > "offers fairly clear benefits" Translation "For us. Muahhaha." At least, until something like this. Hopefully.