5 ms·
I love how simple this worm is. They haven't exploited any security holes (other that looking like Docs), it literally just asks for full access to your email a
by btym 9y ago
I love how simple this worm is. They haven't exploited any security holes (other that looking like Docs), it literally just asks for full access to your email address.
- ehsankia 9y agoYeah, I read articles calling it sophisticated. This is a super simple and straight forward worm. Disguise yourself as a known app and ask for more permission than you should. IDN exploits [0] and attachment faking [1] are more sophisticated if anything. [0] https://www.wordfence.com/blog/2017/04/chrome-firefox-unicode-phishing/ https://www.wordfence.com/blog/2017/04/chrome-firefox-unicod... [1] http://fortune.com/2017/01/18/google-gmail-scam-phishing/ http://fortune.com/2017/01/18/google-gmail-scam-phishing/
- shif 9y agoIt's sophisticated because of it's simplicity and effectiveness.
- chii 9y agoTechnical simplicity, but sophisticated social engineering. Guess what the weakest link is between apps? It sure isnt the tech.
- shmed 9y agoIts sophisticated in the sense that it makes you trust them and willingly share your information with them. It doesn't rely on some brute force method or some complicated hacking method, it simply rely on a modern workflow that people are used to go through without thinking twice about it. It is simple and incredibly efficient.