Google Drive may not be as safe as you expect it to be. The Google service reportedly has a security vulnerability that could allow hackers to send malicious files that appear to look authentic. Google has been notified of the security issue but it hasn’t been patched yet.

This was discovered by A. Nikoci, a system administrator who revealed the Google Drive security flaw to The Hacker News. The issue lies in Google Drive’s “Manage Versions” feature that lets users upload new versions of different files. It essentially lets users restore “an earlier version of a file that wasn’t created in Docs, Sheets, or Slides”.

According to Nikoci, the flaw in this feature allows users to “upload a new version with any file extension for any existing file on the cloud storage, even with a malicious executable.” The process is pretty simple as demoed by Nikoci in three videos. It starts with sharing a normal file via Google Drive. Users can then upload a new version of that file through Manage Version. Here, Nikoci easily uploads an infected version of that file. In doing so, Google doesn’t detect or identify if it’s the same file type or not. Anyone having access to that link can download the infected file.

This security flaw comes at a time when people are using services like Google Drive the most. While its cloud storage has been in use, more people are using it now to share files online due to remote work. This kind of malware can lead to spear phishing attacks that aim to compromise a user’s system.

Google had recently fixed a major security flaw in Gmail that was actually detected four months back. The fix came within seven hours after it was made publicly available. It was also shortly after Google’s services suffered a global outage.

Source: https://tech.hindustantimes.com/tech/news/google-drive-security-flaw-may-let-attackers-send-malicious-files-71598324377151.html

World news – CA – Google Drive security flaw may let attackers send malicious files

En s’appuyant sur ses expertises dans les domaines du digital, des technologies et des process , CSS Engineering vous accompagne dans vos chantiers de transformation les plus ambitieux et vous aide à faire émerger de nouvelles idées, de nouvelles offres, de nouveaux modes de collaboration, de nouvelles manières de produire et de vendre.

CSS Engineering s’implique dans les projets de chaque client comme si c’était les siens. Nous croyons qu’une société de conseil devrait être plus que d’un conseiller. Nous nous mettons à la place de nos clients, pour aligner nos incitations à leurs objectifs, et collaborer pour débloquer le plein potentiel de leur entreprise. Cela établit des relations profondes et agréables.

Nos services:

  1. Création des sites web professionnels
  2. Hébergement web haute performance et illimité
  3. Vente et installation des caméras de vidéo surveillance
  4. Vente et installation des système de sécurité et d’alarme
  5. E-Marketing

Toutes nos réalisations ici https://www.css-engineering.com/en/works/

LEAVE A REPLY

Please enter your comment!
Please enter your name here