Puppy Linux Discussion Forum Forum Index Puppy Linux Discussion Forum
Puppy HOME page : puppylinux.com
"THE" alternative forum : puppylinux.info
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

The time now is Fri 24 Oct 2014, 09:14
All times are UTC - 4
 Forum index » Off-Topic Area » Security
Anonymous creatures viewing my shared file on google drive
Post new topic   Reply to topic View previous topic :: View next topic
Page 1 of 1 [10 Posts]  
Author Message
Barkin


Joined: 12 Aug 2011
Posts: 728

PostPosted: Sun 21 Apr 2013, 06:37    Post subject:  Anonymous creatures viewing my shared file on google drive
Subject description: New anonymous creature icons in google drive
 

Just noticed a weird thing on google drive today : multiple anonymous creatures appear to be viewing a file I intend to share, (see attachment).
However the file is "only those with link" so how do these anonymous creatures know about my file , I haven't sent the link to anyone yet ?
screengrab 130421 of Google drive.gif
 Description   animated screengrab
 Filesize   21.24 KB
 Viewed   495 Time(s)

screengrab 130421 of Google drive.gif

only those with link can view (but I haven't disclosed the link to anyone).gif
 Description   
 Filesize   9.4 KB
 Viewed   530 Time(s)

only those with link can view (but I haven't disclosed the link to anyone).gif

Back to top
View user's profile Send private message 
puppy_apprentice


Joined: 07 Feb 2012
Posts: 135

PostPosted: Mon 22 Apr 2013, 12:10    Post subject:  

i think that somebody wrote script (maybe brute force method) to prepare links and check them if they work, something like:

https://docs.google.com/file/d/XXXXXXXXXXXXXXXX/edit?usp=shari

where XXXXXXXXXXXXXXXX is random number or taken from list of numbers (dictionary)

but if u check part of your link (https://docs.google.com/file/d/) in Google Search u will get some results, try to check this in Google Search:

"https://docs.google.com/file/d/, name of your shared file"

maybe u will find your link
Back to top
View user's profile Send private message 
Barkin


Joined: 12 Aug 2011
Posts: 728

PostPosted: Tue 23 Apr 2013, 05:16    Post subject:  

puppy_apprentice wrote:
i think that somebody wrote script (maybe brute force method) to prepare links and check them if they work, something like:

https://docs.google.com/file/d/XXXXXXXXXXXXXXXX/edit?usp=shari

where XXXXXXXXXXXXXXXX is random number or taken from list of numbers (dictionary)


Accurately guessing XXXXXXXXXXXXXXXXXXXXXXXXXXXXX by brute force would take trillions of centuries : it's about 30 alphanumeric characters, upper and lower case, [ a dictionary wouldn't help as it's random-looking gobbledygook ]

The only legitimate reason for this I can think of is that the anonymous creatures are generated by me viewing the page, as no other user should know the URL of the file I was about to share.

e.g. some token is generated when someone views the page and that token persists in the google system for a few minutes after viewing the page, so if you visit that page again within that period your previous incarnation still exists and is shown by an anonymous creature icon.
Back to top
View user's profile Send private message 
Makoto


Joined: 03 Sep 2009
Posts: 1798
Location: Out wandering... maybe.

PostPosted: Tue 23 Apr 2013, 06:14    Post subject:  

I wouldn't be surprised if they were bots - possibly Google's, to aid in indexing, or even checking to make sure you're not storing anything that shouldn't be there. Neutral

It's probably a good idea to ask Google about it, if at all possible, though.

_________________
[ Puppy 4.3.1 JP, Frugal install | 1GB RAM | 1.3GB swap ] * My Pidgin Builds for Puppy 4.3.1+
In memory of our beloved American Eskimo puppy (1995-2010) and black Lab puppy (1997-2011).
Back to top
View user's profile Send private message 
nooby

Joined: 29 Jun 2008
Posts: 10557
Location: SwedenEurope

PostPosted: Tue 23 Apr 2013, 06:47    Post subject:  

Don't they have a googlegroup for the Drive so
them maybe also has seen these bots?

I know nothing but thought of that they may know?

_________________
I use Google Search on Puppy Forum
not an ideal solution though
Back to top
View user's profile Send private message 
puppy_apprentice


Joined: 07 Feb 2012
Posts: 135

PostPosted: Wed 24 Apr 2013, 05:20    Post subject:  

script with generated XXXXXX is one of the solutions and yes it takes some time, but your link don't have to be sent to anybody to be used, Google Spiders/Bots will add it to the search dadatase i think, it is the same if u upload some files on your server and don't put links to them on your page - they are still easily accesible (eg. via Google Search, some hackers use Google to find eg. files with passwords etc.)

i've checked this in Google Search:

Code:
"https://docs.google.com/file/d/, Barkin"


and found those to files:

https://docs.google.com/file/d/0ByJAC-sfXwumZzI2bVlON2VTMnFyYVZZSnpDYnNyQQ/edit?pli=1

https://docs.google.com/document/d/1wv-PfzG8aGp43ZF-vARPbcJaRRSJWJ8FXlMcQIrOiOo/preview?pli=1

i don't know if you have GD account as Barkin (and it those files are yours), but it is possible to find some files using eg. my phrase in GS

i think it is not problem with security but it is normal GD behavior (and those annonymous creatures could be you own trials too as u said)
Back to top
View user's profile Send private message 
Barkin


Joined: 12 Aug 2011
Posts: 728

PostPosted: Wed 24 Apr 2013, 05:54    Post subject:  

puppy_apprentice wrote:
i've checked this in Google Search:

Code:
"https://docs.google.com/file/d/, Barkin"



I don't use "Barkin" as a pseudonym with Google services.

I just tried googling "https://docs.google.com/file/d/" and my gmail email and thankfully no hits.

Googling the full URL of the shared file (no X's) gets no hits either.
Back to top
View user's profile Send private message 
puppy_apprentice


Joined: 07 Feb 2012
Posts: 135

PostPosted: Wed 24 Apr 2013, 06:07    Post subject:  

so it seems and those was your own trials, and files that i found were published with flag "public" or something (i was using Google Docs some time ago but if i remember well it was possible to save files as public, visible to others) by another user/s
Back to top
View user's profile Send private message 
Barkin


Joined: 12 Aug 2011
Posts: 728

PostPosted: Wed 24 Apr 2013, 07:55    Post subject:  

puppy_apprentice wrote:
... files that i found were published with flag "public" or something ...

More likely someone had actually posted those google URLs on the internet, say in a forum.

puppy_apprentice wrote:
... i was using Google Docs some time ago but if i remember well it was possible to save files as public, visible to others


I've never made my Google Drive files searchable via the web ...
I always choose ''anyone with the link'' , I'ver never tried ''public on the web''.png
 Description   screengrab from Google Drive
 Filesize   7.49 KB
 Viewed   293 Time(s)

I always choose ''anyone with the link'' , I'ver never tried ''public on the web''.png

Back to top
View user's profile Send private message 
puppy_apprentice


Joined: 07 Feb 2012
Posts: 135

PostPosted: Wed 24 Apr 2013, 09:29    Post subject:  

so it seems like u have noticed your own trials, try to prepare another file (honey pot Laughing ) using "only those with link", let the file will be text file with name eg.
Code:
passwords
or
topsecret

and text inside
Code:
"if u got acces to this link, please send me info about it to xxxxxx@xxxxxx or post message in this thread http://murga-linux.com/puppy/xxxxxxxxxx"


who knows, maybe we will get answer if it is something wrong with GD and don't use this link for yourself for a while (week or two) to not get false positives Laughing
Back to top
View user's profile Send private message 
Display posts from previous:   Sort by:   
Page 1 of 1 [10 Posts]  
Post new topic   Reply to topic View previous topic :: View next topic
 Forum index » Off-Topic Area » Security
Jump to:  

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group
[ Time: 0.0695s ][ Queries: 13 (0.0052s) ][ GZIP on ]