Live data from Hacker News

Ask HN: Google Doc email virus?

news.ycombinator.com

81–90 of 220 posts

Re: Ask HN: Google Doc email virus?

#83
When can we expect a public statement regarding the phishing scam and the fallout? We all know it used our accounts to forward itself to everyone in our contact lists, but what about our emails? Have those also been forwarded/harvested? We need to know this to know how to react.

Re: Ask HN: Google Doc email virus?

#85
post #35

Earlier quoted context omitted.

Source code of the worm: https://hastebin.com/gubegaqusi.xml Pretty much what you'd expect. Edit: This isn't the full source code. There was another PHP file visible on their website that unfortunately isn't visible anymore.

On a brief skim, it doesn't seem to do much besides spread itself. Am I missing something, or was it just for lulz? Or maybe a grey hat trying to prove a point?

It redirects to a couple different PHP pages as well, so there could have been more malicious code there

Re: Ask HN: Google Doc email virus?

#87
post #63
post #34

Source code of the worm: https://pastebin.com/raw/EKdKamFq Edit: How I got this: Someone on reddit went to their site when it wasn't down, and downloaded the files linked in the page's HTML. I just posted it here. This isn't the full source code. There was another PHP file visible on their website that unfortunately isn't visible anymore.

I like how the code has Javadoc comments, in case other developers need to maintain the worm or use its public API.

That's gotta be a copy-paste job. If someone was actually cheeky enough to comment their malware they would've left jokes, puns, etc.

Re: Ask HN: Google Doc email virus?

#88
post #71

Earlier quoted context omitted.

> A secure email account is the One True Source of authentication in the digital world. The gmail account you use to talk with people shouldn't be the same one you use to send password resets to. It's fine to allow CRM apps or whatever to have OAuth access to your regular gmail account, you just shouldn't give read-write access to the one you use for your retirement account or whatever. (Read-only access is much less…

> The gmail account you use to talk with people shouldn't be the same one you use to send password resets to. The vast majority of services don't support setting a separate password reset email, so that would be a showstopper for most people. You'd end up just having another email account you have to check all the time (since non-reset email would also go to this account), and could still easily get bitten by this so…

> You'd end up just having another email account you have to check all the time

You'd need an extra tab open in your browser that you'd need to check multiple times per day. But most automated messages don't require a response within fifteen minutes or whatever, so there isn't much extra cognitive overhead. And for most people you probably also don't need that email address authed on your phone.

Re: Ask HN: Google Doc email virus?

#89
post #86

Hi, I'm Google Docs. Would you please grant me access to your Google account so that I can read, send, delete and manage your mail, as well as manage your contacts?

Oh noes, it looks like humanity got hit with a super-sophisticated cyber attack the second time in a day!

Re: Ask HN: Google Doc email virus?

#90
post #35

Earlier quoted context omitted.

Source code of the worm: https://hastebin.com/gubegaqusi.xml Pretty much what you'd expect. Edit: This isn't the full source code. There was another PHP file visible on their website that unfortunately isn't visible anymore.

Heh, they're using Google Analytics to track its spread. That's a nice touch.

"No fair! You got your privacy invasion in my privacy invasion!"
Post reply on HN