15 ms·
Google Docs Users Targeted by Phishing Scam
- juliann 13y agoThis is why EVERYONE should have Two-Step Verification (https://support.google.com/accounts/answer/180744?hl=en https://support.google.com/accounts/answer/180744?hl=en) enabled if you care a little bit about your Google Account and the data you have stored there. This kind of attack will expose your password, but the attackers wont get in your account anyway.
- deleted 13y ago[deleted]
- wtvanhest 13y agoI have it, but one thing to consider when you add Two-step is that you need a plan when you travel overseas and may not have the same sim card. Not difficult to consider, but you still need to. Being in Europe for a few weeks with no email is no fun.
- juliann 13y agoThe two step app works even with no connection to the internet. I dont know how but it does. I think you dont need to have the same sim card. only the phone turned on.
- herge 13y agoI think that the two step code is a hash of a random number shared between Google and the app (when reading the QR code), and the current time.
- tjohns 13y agoGoogle Authenticator uses TOTP (RFC 6238), which means the codes are a function of time plus a secret key. As long as your phone's clock is reasonably accurate, the app will work without any network access. http://tools.ietf.org/html/rfc6238 http://tools.ietf.org/html/rfc6238
- UnfalseDesign 13y agoYou definitely don't need network access. I use Google Authenticator on my Wifi only tablet. You need an internet connection to sync it to Google's key but not after that. And, yes, when the tablet's clock is off by a few minutes, the code doesn't work.
- teraflop 13y agoThat's not a problem if you use the Authenticator app (or a compatible alternative) instead of getting codes over SMS.
- greyskull 13y agoIn that case, use the one-time backup codes and make sure to refresh them every few logins while you're away. I think they give you eight at a time.
- anon1385 13y agoSerious question: what if you don't have a mobile phone?
- axyjo 13y agoGoogle provides you access to one-time codes, if you wish.
- deletes 13y agoI thought you were joking. Sign in using backup codes: https://support.google.com/accounts/answer/1187538?hl=en https://support.google.com/accounts/answer/1187538?hl=en
- eli 13y agoThere's a compatible OTP app for nearly every OS. Ideally you'd be running it on a device that isn't the same as the one running your web browser, but you could just install e.g. a Windows OTP app and use that. Better than nothing.
- shirKahn 13y agoPersonally I use a phone, but I also own a TI Chronos programmable watch that has Google OTP support. The algorithm is fairly straightforward and does not require internet connectivity (through mathematical magic).
- freehunter 13y agoInteresting, I hadn't come across that watch before. How do you like it? Can you compare it to something like a Pebble: size, battery life, screen quality, etc?
- skj 13y agoI don't understand how 2FA completely counters this scam. Consider if you called someone up and told them your password, and then gave them an up-to-date number from your OTP generator. Except instead of calling them up, you're entering it into a fake web page. Certainly the login you just made would not work when you opened up gmail in another window, but all necessary information would have been given to the attacker.
- juliann 13y agoFirst, the scam would be randomly asking for the code or not. Cause it can't know whether the user has 2FA activated or not. So that is one way of noticing that its a scam. 2nd the code only works for 30 seconds or so. I don't know if there's some way of login in through google api's as soon as the user enters the user and password. Also im almost sure that google requires you to enter the code via a form that is provided by them (as a google url). So im thinking something like loggin in to google using server side code and somehow using the code that the user provides to enter into google form (that will be displayed on the server side). Im still not sure if there's any way of doing this using code. If there's no way of doing it using code then the attacker should be fast enough to use your logins and token in less than 30 seconds (or even less when the code is entered later). So it reduces the chances to get attacked a lot.
- euank 13y agoA sophisticated attack can completely imitate 2FA. The first bit: It starts by asking for a username+pass and it uses javascript to async-post it. The evil server then tries to login to google. If google returns that a 2FA is needed it prompts for it. I have no clue what you mean by "through google's api"... An attacker does not have to follow an api. Anything the user can do with their browser, the attacker an imitate on a remote server. Absolutely anything except source ip. Your entire "no way of doing this using code" makes no sense at all. Posting data is something that can easily be done programmatically. Posting data through a middleman is similarly easy. The only way that 2FA helps (edit: as alcari points out, this doesn't help much) is that the attacker can't change your password because on initiating that, I believe google asks for another 2FA code, and I don't think the attacker could reasonably expect to get you to enter two 2FA in a row. It also does make it harder for the attacker to code it up, but it's not even that much harder.
- ikarandeep 13y agoAgreed 100% However, hopefully you aren't using the same password on other sites. And hopefully you don't plan to use the same password on other sites in the future.
- iancarroll 13y agoIt's interesting how this is done - and there's no real workaround except to force 2FA.
- eli 13y agoHow does 2FA solve this? You're interacting with an attacker who is prompting you for information in real time.
- TrainedMonkey 13y agoRight. This is MITM attack and they can defeat most of 2FA out there today. One technique that might help is to make user choose a picture during account registration. During login show that picture, if user does not see correct picture he would suspect something. It does not have to be picture, could be style or background of login component.
- eli 13y agoIf the server just knows what picture is attached to my account, couldn't this attacker simply request the picture on my behalf and then show it to me?
- juliann 13y agoThat information would obviusly not be accessible via ANY api. So that would be something only Google private apps have access to.
- deleted 13y ago[deleted]
- georgemcbay 13y agoDoesn't really matter if there is an API for it or not, if Google were to display it prior to you being authenticated (which they would have to for it to have any impact in this sort of attack), it would be fairly trivial for the attack code to (behind the scenes) present themselves as you to Google and then scrape the correct image from Google's response to their request. There are various things Google could do to make this more difficult, like some fancy rendering via canvas or webgl instead of just using a bog standard img tag, but to counter this the attack could just run a headless rendering browser and pixel scrape the resulting image. Such a verification image makes the MITM attack a bit harder to code, but not really by much, and in the process might introduce an increased false sense of security.
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- zaroth 13y agoWhat's to stop the attacker from going the next step and forwarding the user/pass to Google, triggering the SMS for 2FA, and then prompting me to enter it? Now all you can hope is that Google notices the source IP or user-agent of the attacker doesn't match up with the user's usual pattern.
- johns 13y agoIf they use CSRF tokens, this wouldn't be possible.
- rabbidruster 13y agoI don't see how CSRF tokens apply here. They can login as you on another machine.
- hahainternet 13y agoYou did not read the parent comment. They cannot (or should not) be able to forward the login to Google's real form and trigger SMS 2FA because the real form should be protected by CSRF tokens.
- eli 13y agoNo, CSRF isn't relevant. I'm an attacker and I have a server that's pretending to be a Google login form. I also have a client computer with a scripted browser pretending to be someone trying to login to Google. When you come to my page and login, I steal your data and immediately have my client program use it to login. If Google asks my client browser for a 2FA code, behind the scenes I forward that request to you and then when you answer, I forward the answer back to Google. From what Google can see, it just looks like someone logging in from a new computer. None of this has anything to do with cross-site scripting. It's a MITM attack. CSRF doesn't come into play.
- ntakasaki 13y agoThat's not what CSRF protects against and neither is it meant to. CSRF happens when you try to submit a form hosted on your site to a target site that the user has already authenticated to. Here, the real form can be accessed from the attacker's browser, not the victim's, hence the attacker knows the CSRF tokens. CSRF doesn't protect against phishing.
- brown9-2 13y agoAfter pressing "Sign in", the user’s credentials are sent to a PHP script on a compromised web server. I might be missing something, but how does this part work? Is it because the document in the Google Drive folder is actually a html document that the browser is loading (and executing javascript of)?
- C1D 13y agoIt's probably using a form tag in the html. The data entered would be sent as a POST request to the external site. Or it could be trough JavaScript which would Ajax the data to the external site.
- jontas 13y agoThe latter would require a cross domain ajax request, I'm sure it is just a regular form POST.
- eam 13y agoMy guess would be: Using something like:<form action="somebadsite.com/script.php"> So the credentials entered get submitted to the form which is sent via POST request to an external server. From there they can do whatever they want with the credentials (perhaps save them to a db) then redirect back to google docs.
- eli 13y agoAFAIK, it's not a legitimate login form. It's a attacker-created form that just looks like the login form. The trick is that they used Google Docs to host it on a .google.com server.
- brown9-2 13y agoThanks, the article was not very clear about that part.
- somerandomness 13y agoit wasn't actually hosted on a .google.com domain. It was googledrive.com, which is also owned by Google, but you should never expect a login form on that domain.
- semenko 13y agoSurprised no one's used this opportunity to talk about Google's gnubby / FIDO / U2F plans. Non-phishable two-factor auth token: http://fidoalliance.org/ http://fidoalliance.org/ See presentation: https://docs.google.com/a/google.com/presentation/d/16mB3Nptab1i4-IlFbn6vfkWYk-ozN6j3-fr7JL8XVyA/edit#slide=id.g19c09a112_2_0 https://docs.google.com/a/google.com/presentation/d/16mB3Npt...
- peterkelly 13y agoSure, I'll just click on that google docs link to read about it...
- aawc 13y agoThe pathname "/a/google.com" means it does come from within Google.
- RKearney 13y agoNo, it doesn't. You can put any valid Google Apps domain there. See: https://docs.google.com/a/google.com/document/d/1MBxYZ9C51t9sqL83D3T5708eRk05WaYbE1Dw0qX-iB8/ https://docs.google.com/a/google.com/document/d/1MBxYZ9C51t9... If you're logged into a Google Apps domain it will change the google.com to match your domain. If you're logged into a regular Google account it will remain as google.com.
- judk 13y agoThe domain name being Google.com means it is protected by Google's security policy. But don't necessarily trust links inside that doc...
- dhekir 13y agoSince we are talking about phishing in Google's domains, can someone explain me why http://www.blogspot.co.uk http://www.blogspot.co.uk (and .ie, and .fr, etc.) leads to someone's specific blog, instead of doing like the http://www.blogspot.com http://www.blogspot.com site does, which leads to Google's login? What prevents this "www" Blogger user from mounting a phishing attack?
- judk 13y agoNice, www.neocities.com had a similar flaw.
- mikeash 13y agoAnd that's why you shouldn't serve user content on the same domain as your own stuff.
- timothya 13y agoWhich they don't. Google Drive data is served from a different URL for precisely this reason.
- mikeash 13y agoThey use a different subdomain, but both the official login page and user docs are served from a *.google.com hostname. I'm not sure if that counts or not.
- timothya 13y agoThe real login page is on a *.google.com domain, of course. But this phishing scheme is on a different domain, namely https://googledrive.com/.. https://googledrive.com/...
- mikeash 13y agoGood! I tried loading a document of my own but only figured out how to get a preview and a download. Shouldn't have extrapolated from there, I guess.
- therealmarv 13y agoI think it is important that Symantec should mention how the URL looks like. From reading this news I can only assume that this happens with hosted websites from Google Drive which have an URL like https://googledrive.com/host/someidhere https://googledrive.com/host/someidhere This warning could be better.
- mathattack 13y agoI've seen an account hacked already.
- judk 13y ago> Symantec customers are protected against this threat. How?