+ Reply to Thread
Results 1 to 1 of 1

Windows 7 Forum

Malware hides from search engines

Fix and Repair Windows 7

  1. #1
    reghakr's Avatar
    reghakr is offline Tier 2 Moderator Valued Contributor reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute reghakr has a reputation beyond repute
    • Computer Specs
      • OS: Windows 7 64-nit
      • Computer Type: E-Machines (Customized
      • Processor: AMD Athlon™ II X2 250u Processor 1.60GHz Max 1.60GHz Ext 200MHz Cores 2 Threads 2
      • Motherboard: eMachines
      • Video Card: NVIDIA GeForce 8500 GT 512 MB memory with HDMI out
      • Memory: 6GB DDR2 RAM DIMM Speed 266MHz
      • Hard Drive: Seagate ST375052 8AS (500GB) and WD25 00AAKS-00VSA (250GB)
      • Network Adapter: NVIDIA nForce 10/100 Mbps Ethernet
      • Monitor: Acer 22" widescreen DVI out
      • Anti-virus Software: PC Tools Spyware Doctor with Anti-virus
      • Windows Experience Index: 4.5
    Join Date
    Jan 2009
    Posts
    10,000
    My Mood
    Mellow
    Rep Power
    3093


    Did you find this post helpful? Yes | No

    Malware hides from search engines

    Criminals are increasingly attempting to conceal malware embedded in hacked websites from search engines such as Yahoo! and Google. Their aim is to prevent browsers which use technology such as Google's Safe Browsing API from sounding the alarm when a user visits a hacked website. Google's Safe Browsing API allows client applications to query Google's phishing and malware blacklist. Firefox and Google Chrome both make use of the API, which is based on

    Google searches of websites for suspicious code.

    If a Google search bot reaches one of these sites that conceal malware, it is recognised and simply fed harmless code. Web applications can identify visits from Google from the IP address and from the user agent (googlebot, yahoo) and can then use this information to control optional redirects to other pages. This can be achieved with just a few lines of code inserted into a hacked PHP web application. Fraudsters often use compromised websites, but also sometimes use special blog software.

    Serving this kind of browser-specific content is nothing new, but it has previously tended to be used by developers to deliver different code to Internet Explorer and Firefox due to different functions. Blogger Brian Krebs quotes Google as confirming that criminals are using these kinds of tricks. Niels Provos of Google even adds that when search bots reach the infected sites they are directed to current content extracted from news sites, helping to increase the ranking of the infected site and making it more likely to attract victims. When an ordinary user then follows the link from the search engine they are fed the malicious code. Google is reported to be instituting counter-measures to combat such tricks, but is declining to release details, noting that it is engaged in a constant arms race with criminals.


    See also:
    Last edited by reghakr; 04-26-2010 at 07:52 AM.
    Yes, that my license plate
    I think I'm on the FBI list.



+ Reply to Thread

Similar Threads

  1. How to Remove Facebook Profile from Search Engines
    By reghakr in forum Security Zone
    Replies: 0
    Last Post: 02-09-2010, 07:39 AM
  2. Top search results riddled with malware
    By reghakr in forum Security Zone
    Replies: 0
    Last Post: 02-08-2010, 09:02 AM
  3. New botnet hides commands as JPEG images
    By reghakr in forum Security Zone
    Replies: 0
    Last Post: 10-01-2009, 11:07 AM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
Microsoft Partner Network