TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Recently I was targeted by an sophisticated (Google) phishing attack

5 pointsby mikexstudiosabout 1 month ago

1 comment

parliament32about 1 month ago
&gt; Next, they create a Google OAuth application. For the name of the application, they enter <i>the entire text of the Phishing message</i> - newlines and all - followed by a lot of whitespace, and &quot;Google Legal Support&quot;.<p>So the meat of the issue is.. Google allows very long oauth application display names, which can look like an email body when they send notifications about that application?<p>In Microsoft-land this field (&quot;display name&quot;) is limited to 120 characters.