Ask HN: Google Doc email virus?
31–40 of 220 posts
Re: Ask HN: Google Doc email virus?
#32Looks like this is fairly widespread. This is what the attack actually looks like: https://twitter.com/zachlatta/status/859843151757955072
I guess that probably just means someone working there got it though.
Re: Ask HN: Google Doc email virus?
#33Re: Ask HN: Google Doc email virus?
#34Edit: How I got this:
Someone on reddit went to their site when it wasn't down, and downloaded the files linked in the page's HTML. I just posted it here.
This isn't the full source code. There was another PHP file visible on their website that unfortunately isn't visible anymore.
Re: Ask HN: Google Doc email virus?
#35EDIT: According to a Google representative on the reddit thread, this application is now blocked. If your account was affected, you no longer need to do anything. If you fell for this, changing your password is not the right solution - you want to log into your google account and remove permissions from the application. https://myaccount.google.com/permissions?pli=1 should show a list of apps connected to your accoun…
Pretty much what you'd expect.
Edit: This isn't the full source code. There was another PHP file visible on their website that unfortunately isn't visible anymore.
Re: Ask HN: Google Doc email virus?
#36Anyone know how far spread this is? it just Hit our school emails
Thankfully, the attack method means Google just has to shut off the app in their systems (which they appear to have done).
Re: Ask HN: Google Doc email virus?
#37Re: Ask HN: Google Doc email virus?
#38It looks like Google removed (at least one of) their access tokens
Checked the URL containing:
googledocs.g-docs.win%2Fg.phpRe: Ask HN: Google Doc email virus?
#39Our support team is getting spammed a lot from our customers. We're in the education space, and it's spreading pretty quick. On initial inspection the URL looks harmless, but it's got some malicious params in there, mainly redirect_uri=https%3A%2F%2Fgoogledocs.g-docs.win%2Fg.php It appears to request read/send access to your email, and then spam all your contacts