|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4807 Location: USA
|
Posted: Wed Nov 28, 2007 12:14 am Post subject: Google search malware attack in progress |
|
|
FYI...
- http://preview.tinyurl.com/2db83x
November 27, 2007 (Computerworld) - "A large-scale, coordinated campaign to steer users toward malware-spewing Web sites from Google search results is under way, security researchers said today. Users searching Google with any of hundreds of legitimate phrases -- from the technical "how to cisco router vpn dial in" to the heart-tugging "how to teach a dog to play fetch" -- will see links near the top of the results listings that lead directly to malicious sites hosting a mountain of malware. "This is huge," said Alex Eckelberry, Sunbelt Software's CEO. "So far we've found 27 different domains, each with up to 1,499 [malicious] pages. That's 40,000 possible pages." Those pages have had their Google ranking boosted by crooked tactics that include "comment spam" and "blog spam," where bots inundate the comment areas of sites with links or mass large numbers of them as bogus blog posts. Attackers may be using bots to plug links into any Web form that requests a URL, added Sunbelt malware researcher Adam Thomas. There's no evidence that the criminals bought Google search keywords, however, nor that they've compromised legitimate sites. Instead, they've gamed Google's ranking system and registered their own sites... One site that Thomas encountered tried to install more than 25 separate pieces of malware, including numerous Trojan horses, a spam bot, a full-blown rootkit, and a pair of password stealers. All the malicious code pitched at users is well-known to security vendors, and can only exploit PCs that aren't up-to-date on their patches... Sunbelt's company blog sports screen shots* of several Google search results lists, with malware-infecting sites identified, as well as images of the bogus codec installation dialogs and the code of one of the malicious IFRAMEs."
* http://sunbeltblog.blogspot.com/2007/11/breaking-massive-amounts-of-malware.html
 _________________ AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4807 Location: USA
|
|
| Back to top |
|
 |
mrsugg
Special Response Team Premium Member
 Joined: Aug 15, 2006 Posts: 2758 Location: Somewhere, over the rainbow...
|
Posted: Wed Nov 28, 2007 3:51 pm Post subject: |
|
|
Will using Siteadvisor alert users to these malicious sites? _________________ "We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4807 Location: USA
|
Posted: Wed Nov 28, 2007 4:02 pm Post subject: |
|
|
| Quote: | | Will using Siteadvisor alert users to these malicious sites? |
...maybe, if they update their database fast enough, ya' think?
| Quote: | | ...40,000 possible pages. |
...is ALOT of updates.
 _________________ AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
|
|
| Back to top |
|
 |
mrsugg
Special Response Team Premium Member
 Joined: Aug 15, 2006 Posts: 2758 Location: Somewhere, over the rainbow...
|
Posted: Wed Nov 28, 2007 4:21 pm Post subject: |
|
|
true..
Best to make sure that EVERYTHING is up to date. _________________ "We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
|
|
| Back to top |
|
 |
mechBgon
Lieutenant

Joined: May 13, 2007 Posts: 216
|
Posted: Wed Nov 28, 2007 5:09 pm Post subject: |
|
|
| mrsugg wrote: | | Will using Siteadvisor alert users to these malicious sites? |
In my experience as a SiteAdvisor reviewer, the chances are not very good. Their reaction time can be on the order of >6 weeks and they frequently mis-rate malicious sites when they finally do get around to it. _________________ Vista x64 · non-Admin account + Software Restriction Policy · Kaspersky AntiVirus 7 · Windows Firewall · full hardware DEP · 64-bit IE7 PM
|
|
| Back to top |
|
 |
mrsugg
Special Response Team Premium Member
 Joined: Aug 15, 2006 Posts: 2758 Location: Somewhere, over the rainbow...
|
Posted: Wed Nov 28, 2007 8:21 pm Post subject: |
|
|
Thanks, mechBgon. WOW! Over 6 weeks! I'm glad that I don't depend on it too much. _________________ "We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4807 Location: USA
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2933
|
Posted: Thu Nov 29, 2007 4:20 am Post subject: |
|
|
| mechBgon wrote: | | mrsugg wrote: | | Will using Siteadvisor alert users to these malicious sites? |
In my experience as a SiteAdvisor reviewer, the chances are not very good. Their reaction time can be on the order of >6 weeks and they frequently mis-rate malicious sites when they finally do get around to it. |
With respect, I disagree. Granted, McAfee Site Advisor can be slow in changing site ratings based on user-driven reviews, especially if the reviewer has a low approval ranking, or there are few reviews on a site, or reviews are mixed. That's when you can get a long elapsed period such as you quote.
However, Site Advisor has separate feeds into the rating system from trusted sources, which I am not at liberty to divulge. Those are faster and instantaneous.
- - - - -
Been there, done that, got the Site Advisor T-shirt!
(Experienced Reviewer, level 9)
|
|
| Back to top |
|
 |
mechBgon
Lieutenant

Joined: May 13, 2007 Posts: 216
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4807 Location: USA
|
Posted: Thu Nov 29, 2007 1:14 pm Post subject: |
|
|
Ongoing...
- http://isc.sans.org/diary.html?storyid=3700
Last Updated: 2007-11-28 23:06:30 UTC ...(Version: 4)
"UPDATE: Live Search has submitted the changes necessary to yank these URLs from the database."
 _________________ AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
|
|
| Back to top |
|
 |
harrywaldron
Microsoft MVP
 Joined: Aug 15, 2005 Posts: 113 Location: USA
|
|
| Back to top |
|
 |
mrsugg
Special Response Team Premium Member
 Joined: Aug 15, 2006 Posts: 2758 Location: Somewhere, over the rainbow...
|
|
| Back to top |
|
 |
harrywaldron
Microsoft MVP
 Joined: Aug 15, 2005 Posts: 113 Location: USA
|
Posted: Thu Nov 29, 2007 6:34 pm Post subject: |
|
|
I have have spoken too soon, as a new batch of .cn sites are starting to show up, according to Sunbelt ...
Internet Search poisoning - 2nd wave could be on the way?
Sunbelt is reporting new seedings for the .cn domain (China) oriented websites in Google (and this could possibly show up in other search engines). The sites are not launching exploit attacks yet, but this could change.
What to avoid: Avoid unusual sites with random letter/number combos, numerical IP addresses, and sites which end in a domain name of "cn" from Internet searches.
HEADS UP: More Google poisoning on the way?
http://sunbeltblog.blogspot.com/2007/11/heads-up-more-google-poisoning-on-way.html
| Quote: | Google has removed the sites responsible for the recent massive Google poisoning attack. However, we’re seeing indications that another attack may be on the way. We have seen another spate of websites freshly registered, using the similar .cn domains. There seem to be two different groups here.
Right now, we’re not seeing either site serve exploits, as we saw in the last attack. However, this could change. |
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4807 Location: USA
|
Posted: Fri Nov 30, 2007 1:51 pm Post subject: |
|
|
FYI...
- http://preview.tinyurl.com/3cgt5k
November 30, 2007 (Computerworld) - "Google is asking everyday Web surfers to help with its efforts to stamp out malicious Web sites. The company has created an online form designed to make it easy for people to report sites they suspect of hosting malicious code. It's the latest step by Google to expand its database of the bad Web sites it knows about, as those sites continue to proliferate. "Currently, we know of hundreds of thousands of Web sites that attempt to infect people's computers with malware. Unfortunately, we also know that there are more malware sites out there," Google's Ian Fette wrote in the company's security blog*..."
* http://googleonlinesecurity.blogspot.com/2007/11/help-us-fill-in-gaps.html
- http://msmvps.com/blogs/spywaresucks/archive/2007/11/30/1371503.aspx
November 30, 2007 - "...(Google) blog entry was published after Sunbelt reported the massive seeding of malicious web sites on Google (which were *not* flagged as dangerous), which was then cleaned up, and before it was reported that nonsense domains were reappearing in Google's search, albeit with (apparently) no malicious content (yet)... The innocent days of the Internet as a wonderous, safe place that all can visit, and learn, and teach and share and explore without fear is gone. The criminals have taken that dream away from us. That is the reality..."
 _________________ AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
|
|
| Back to top |
|
 |
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|