←back to thread

156 points abirag | 8 comments | | HN request time: 0.336s | source | bottom
1. nwellinghoff ◴[] No.45307850[source]
How does a random user get a document in your notion instance?
replies(5): >>45307876 #>>45307919 #>>45308473 #>>45308804 #>>45310975 #
2. cobertos ◴[] No.45307876[source]
People put all kinds of stuff in Notion. People use it as a DB. People catalog things they find online (web clipper). There's collaboration features.

There are many ways

replies(2): >>45308540 #>>45310985 #
3. Lalabadie ◴[] No.45307919[source]
The article gives a PDF document as an example, but depending on how links are opened and stored for Notion agents, threat actors could serve a different web page depending on the crawler/browser agent.

That means any industry-known documentation that seems good for bookmarking can be a good target.

4. memothon ◴[] No.45308473[source]
Lots of companies have automations with Zapier etc. to upload things like invoices or other documents directly to notion. Or someone gets emailed a document with an exploit and they upload it.
5. PokestarFan ◴[] No.45308540[source]
If I had to describe it, Notion is if somehow managed to combine OneNote and Excel. Of interest is the fact that the "database" system stores each row as a page with the column values other than title stored in a special way. Of course, this also means that it doesn't scale at all, but I have seen some crazy use cases (an example is replacing Jira).
6. simonw ◴[] No.45308804[source]
In this case by emailing you a PDF with a convincing title that you might want to share with your coworkers - the malicious instructions are hidden as white text on a white background.

There are plenty of other possibilities though, especially once you start booking up MCPs that can see public issue trackers or incoming emails.

7. freakynit ◴[] No.45310975[source]
Google "best free notion marketing templates" and then import them. I have done them multiple times, and so does 1000's of others woldwide.
8. freakynit ◴[] No.45310985[source]
Notion is like the "dump-truck" of everything lol.