Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

May 30th, 2011, 17:58 GMT · By

Phishers Store Rogue Forms on Google Docs

SHARE:

Adjust text size:


Google Docs abused by phishers
Enlarge picture
Security researchers from Finnish antivirus vendor F-Secure have found phishing forms stored as spreadsheets on Google Docs, outlining yet another way in which legitimate services are being abused by cyber criminals.

The F-Secure researchers have found several such rogue spreadsheets which seem to be part of different phishing campaigns.

"Spreadsheets can even contain functionality, such as forms, and these can be published to the whole world. Unfortunately, that means we regularly see phishing sites via Google Docs spreadsheets and hosted on spreadsheets.google.com," says F-Secure's Chief Research Officer, Mikko Hypponen.

In one case, a spreadsheet titled "webmail account upgrade" contains fields for inputting webmail account credentials. In another, a form is gathering student data.

One page, claiming to be a Google Voice account transfer form, is crafted so well that not even the F-Secure researchers are sure if it's legitimate or not.

On one hand it asks for Google Voice numbers, e-mail addresses and secret PIN codes, so it looks like a phishing scam, but on the other, Google employees have linked to it on support forums.

This is not the first time when cyber criminals have abused Google Docs. The practice of storing documents with pharma spam on the popular service was quite common a year ago.

At one point their numbers became so high that Spamhaus, a renowned anti-spam outfit, added the Google Docs servers to its blacklist.

One big issue with this kind of abuse is that it leverages the site's SSL protection to lend itself more credibility. Users have been told repeatedly to make sure they are on SSL-enabled websites when inputting personal information, based on the fact that phishers don't set up digitally signed pages.

However, seeing the SSL padlock in the address bar and the fully encrypted connection with Google Docs might lead users to think that these are legitimate forms.

TELL US WHAT YOU THINK:

1,077 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Spamhaus Adds Gmail to Block List [Updated]

Google Video SEO Poisoning

Google Could Be Used to Control Botnets

Trojan Found Hosted on Google

READER COMMENTS:


Comment #1 by: Teksquisite on 31 May 2011, 10:43 UTC reply to this comment

"webmail account upgrade" is a legitimate Google doc created by Google.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM