Digital Point Forums
Wester Union

Go Back   Digital Point Forums > Search Engines > Google
Google Analytics
Log In to view
your analytics

Reply
 
Thread Tools
  #1  
Old Nov 28th 2007, 10:29 am
samantha pia's Avatar
samantha pia samantha pia is offline
Banned
 
Join Date: Dec 2004
Location: Give, Denmark
Posts: 4,506
samantha pia has a reputation beyond reputesamantha pia has a reputation beyond reputesamantha pia has a reputation beyond reputesamantha pia has a reputation beyond reputesamantha pia has a reputation beyond reputesamantha pia has a reputation beyond reputesamantha pia has a reputation beyond reputesamantha pia has a reputation beyond reputesamantha pia has a reputation beyond reputesamantha pia has a reputation beyond reputesamantha pia has a reputation beyond repute
Google search results delivering massive malware attacks

For the last two days, security software firm Sunbelt Software has been all over what could develop into a scary trend: Rigged Google search results that deliver big malware payloads.

source http://blogs.zdnet.com/security/?p=688&tag=nl.e622

On Monday, Sunbelt reported “we’re seeing a large amount of seeded search results which lead to malware sites.” The search terms leading you to these malware payloads were pretty basic fare.

This screenshot courtesy of Sunbelt shows an example of the malware sites (Sunbelt’s post has a bunch of other examples).



On Tuesday, Sunbelt researcher Adam Thomas followed up with another post. Thomas wrote:

Sunbelt Software has uncovered tens of thousands of individual pages that have been meticulously created with the goal of obtaining high search engine ranking. Just about any search term you can think of can be found in these pages.

Simply put, damn near any Google search term–even terms like “hospice”– can take you to one of these malware sites. Computerworld quotes Sunbelt Software CEO Alex Eckelberry as saying “this is huge.” I’m inclined to agree, especially considering Eckelberry’s inventory: “27 different domains, each with up to 1,499 [malicious] pages. That’s 40,000 possible pages.”

Thomas continues:

For months now, our Research Team has monitored a network of bots whose sole purpose is to post spam links and relevant keywords into online forms (typically comment forms and bulletin board forums). This network, combined with thousands of pages such as the two seen above, have given the attackers very good (if not top) search engine position for various search terms.

In our previous post, we mentioned that the malicious pages also contained an IFRAME link which would attempt to exploit vulnerable systems. If you were unlucky enough to run across one of these links while surfing with a vulnerable system, you would become infected with a family of malware that we call Scam.Iwin. With Scam.Iwin, the victim’s computer is used to generate income for the attacker in a pay-per-click affiliate program by transmitting false clicks to the attacker’s URLs without the user’s knowledge. The infected Scam.Iwin files are not ordinarily visible to the user. The files are executed and run silently in the background when the user starts the computer and/or connects to the internet.

Google has been notified and hopefully its fancy algorithm can nuke these bogus sites pronto.
Reply With Quote
  #2  
Old Nov 28th 2007, 11:04 am
alex_d1's Avatar
alex_d1 alex_d1 is offline
of the Nightfall
 
Join Date: Jun 2007
Location: Greece.fm
Posts: 1,434
alex_d1 is a jewel in the roughalex_d1 is a jewel in the roughalex_d1 is a jewel in the rough
With sites such as these, I would guess that Google should start deleting them manually from their index, rather than waiting for the next index.

Its pretty worrying when pages who se sole purpose is to deliver malware start achieving such high positions on Google. From the image posted above, all the dodgy sites look to be .cn, so that's a good enough reason for me neither to click on a weird looking url with that extension.
__________________
Use Adsense but have no Privacy Policy ? Create your Adsense Privacy Policy
Reply With Quote
  #3  
Old Nov 28th 2007, 11:11 am
mizaks's Avatar
mizaks mizaks is offline
of the Nightfall
 
Join Date: Jan 2007
Location: thecriticalcritics.com
Posts: 1,981
mizaks is a name known to allmizaks is a name known to allmizaks is a name known to allmizaks is a name known to allmizaks is a name known to allmizaks is a name known to all
All fom China . . . I generally don't visit many links from Russia or China
__________________
------------------------------------------------
Movie Reviews by The Critical Critics | Movie Critics Wanted!
------------------------------------------------
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Google Adsense for Search: Big gap after search results Azam.biz Placement / Reviews / Examples 18 Aug 15th 2008 6:46 am
Q.Google Search results: Extra results for specific areas of a website larssonk22 Google 4 Jun 29th 2007 9:14 am
Getting Massive Traffic From Google Image Search? Claymation Google 15 Apr 8th 2007 5:47 am
Digg Request: Results of the MASSIVE Google Ban - 7 BILLION Pages Nintendo Services 5 Jun 22nd 2006 4:13 pm
Massive difference between google.com and Big Daddy results. JackR Google 1 Jan 31st 2006 1:04 am


All times are GMT -8. The time now is 8:30 am.