Phishing alert! This Google Drive feature has a security flaw, can fool you into installing malware

The approach used to propagate malware could be used for spear phishing attacks.

Agencies
The cloud storage service does not reportedly check whether the online preview of a file is of the same type as that stored in Google Drive.
Hackers could fool you into installing malware using a feature offered by Google Drive. According to a system administrator, A. Nikoci, a flaw in Google Drive’s “manage versions” feature could provide hackers with an opportunity to swap a legitimate file stored in one’s Drive, with malware of the same file type.

The cloud storage service does not reportedly check whether the online preview of a file is of the same type as that stored in Google Drive. Seemingly innocuous selfies may actually be malevolent programs in disguise.

It is difficult to spot such sleights as the online preview does not raise any red flags, so users might not know they are looking at a problematic file till they’ve installed it. Further, Google’s Chrome browser implicitly trusts Drive downloads even if third-party antivirus programs set the alarm bells ringing.



The approach used to propagate malware could be used for spear phishing attacks that trick users into giving malicious programs access to their systems. Especially for accounts where access is shared, users might get a notification about a document being updated, and the file might be downloaded without realising the threat.

Nikoci wrote that he notified Google about the problem. They did not issue a software patch, as of August 22. This could impact companies that use Google Drive for file-sharing among employees, especially if those contain sensitive information. In a separate incident, Gmail and other GSuite apps faced “service disruption” last week.

ADVERTISEMENT
Safety Nets, Cookie Control & Secure DNS: Follow These Simple Google Chrome Hacks To Keep Data Safe
1/5

Google Chrome, in all probability, might be the most commonly-used browser, but it has been at the centre of criticism due to controversial changes, security problems and data concerns.

From Chrome 79 accidentally deleting data for Android users in December 2019, Chrome 80’s ‘high level vulnerabilities’ that put data at risk to the controversial deep linking upgrade in February 2020 that allegedly compromised on privacy, Chrome has often left its users worried about their safety and security.

However, Chrome has now put all the privacy and security concerns to rest with its new upgrade. A blog post on Google’s website titled, ‘More intuitive privacy and security controls in Chrome’, breaks down the security updates in detail. Here are some of them:

Google Chrome, in all probability, might be the most commonly-used browser, but it has been at the centre of criticism due to controversial changes, security problems and data concerns.From Chrome 79..
Read More

Most of us use the incognito mode in Google Chrome for private browsing. The USP of Google’s incognito mode is that it does not save history, information entered by the user in forms or browser cookies. The good folks at Google have now decided to take security and privacy in incognito mode a notch higher.

You can now control whether you wish to allow third-party cookies in incognito mode. Chrome will now block third-party cookies by default in incognito mode. If you wish to allow third-party cookies for specific sites, you can click the ‘eye’ sign on the address bar.

The feature, as per Google’s blog, will be gradually rolled out. For the uninitiated, third-party cookies allow websites to track a user across the web. With Chrome’s new update, you can keep your information secure by blocking these cookies.

Most of us use the incognito mode in Google Chrome for private browsing. The USP of Google’s incognito mode is that it does not save history, information entered by the user in forms or browser cooki..
Read More

Security attacks such as phishing and malware have become quite common on the internet. To combat the menace, Google Chrome now has a security update that users can opt for. Called ‘Enhanced Safe Browsing’, this security upgrade will allow Chrome to proactively detect phishing attacks, malware and other web based threats.

Chrome will do this by proactively checking if pages and downloads are dangerous by sending information about them to Google Safe Browsing.

Going forward, Google will also add more protections to this upgrade such as tailored warnings for phishing sites, file downloads, cross product alerts and more.

Security attacks such as phishing and malware have become quite common on the internet. To combat the menace, Google Chrome now has a security update that users can opt for. Called ‘Enhanced Safe Bro..
Read More

Another security upgrade that Chrome has come up to protect your privacy is ‘Secure DNS’.

When we enter a website in the address bar of the browser, it first needs to determine which server is hosting the website. This step is called DNS (Domain Name System) lookup.

Google Chrome’s Secure DNS feature will encrypt this step using ‘DNS-over-HTTPS’. This will not allow the attackers to find out which website you want to visit and they won’t be able to send you phishing webpages.

Another security upgrade that Chrome has come up to protect your privacy is ‘Secure DNS’. When we enter a website in the address bar of the browser, it first needs to determine which server is hostin..
Read More

Apart from introducing strong security measures to keep attackers at bay, Google has also developed a safety net for its users. With the help of a safety check in Chrome, you can make sure that your data is safe.

For starters, Chrome has come up with a new tool that will tell you if the passwords that you have asked Chrome to remember have been compromised and if so, how to fix it.

Secondly, Chrome will raise a red flag if ‘Safe Browsing’, Google’s technology to warn you when you are about to access a dangerous website, has been turned off.

The safety check tool will also help you determine if you are using the latest version of Google Chrome. It will also let you know if malicious extensions have been installed and how to remove them.



Apart from introducing strong security measures to keep attackers at bay, Google has also developed a safety net for its users. With the help of a safety check in Chrome, you can make sure that your ..
Read More

Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › Magazines › Panache › Phishing alert! This Google Drive feature has a security flaw, can fool you into installing malware
Text Size:AAA
Success
This article has been saved

*

+