Monday, November 7, 2011

beware of malicous google calendar invites - food for thought

It would appear that it is completly possible and with ease to send meeting invites which contain executables using gmail and google calendar.

This is how it will appear in the inbox of an unsuspecting human:
Now the attachment is hosted on Google docs, from which you would need to download and run it.

I know, I know, It isn't really an "evil attachment" it is just a link to an executable...
but, it is a google calendar invite hosting a link to an executable file on google docs.

now I know a few people who aren't as paranoid as me and would trust google hosted files more then just a random hosted file on some unknown server, but then again, that is just me :)

Food for thought.

