Europe Web Hosting Directory
» about us  
» advertising  
» contact  
  » home     » low cost web hosting     » business class hosting                            
Unix Windows Budget Reseller Shared Dedicated
Find Hosting Providers By Country
United Kingdom | Germany | France | Italy | Spain | Romania | Netherlands | Portugal | Czech Rep. | Sweden | Greece | Austria | Switzerland | Denmark | Slovakia | Ireland | Norway | Estonia | Latvia | Lithuania | Slovenia | Croatia | Finland | Luxembourg | Russia | Ukraine | Serbia & Montenegro | Bosnia & Herzegovina | Poland | Bulgaria | Hungary |
Malicious Websites Shut Down Thanks to Google

Malicious Websites Shut Down Thanks to Google - 2007-12-01

The booby-trapped websites came up in search results for search terms such as "Christmas gifts" and "hospice".

Windows users falling for the trick risked having their machine hijacked and personal information plundered. The criminals poisoned search results using thousands of domains set up to convince search index software they were serious sources of information.
Innocent victim

While computer security researchers have seen small-scale attempts to subvert search results before now, the sheer scale of this attack dwarfed all others. "This was fairly epic," said Alex Eckelberry, head of Sunbelt Software - one of the firms that uncovered the attack.

Mr Eckelberry said tens of thousands of domains were used in the vanguard of the attack. Most domains were Chinese registered, hosted in the US and were only a couple of days old. Websites loaded on these domains were booby-trapped with malicious software that looked for vulnerabilities in copies of Microsoft's Internet Explorer used to browse them.
"If your machine was not fully patched you were going to get hosed," said Mr Eckelberry.

The criminals who bought the domains convinced the indexing software used by Google, MSN and Yahoo they were good and popular sources of information, said Mr Eckelberry. Although the results were indexed by Yahoo and MSN the webpages were coded to only show up if someone used Google.

They accomplished this using comment spam on blogs to push the pages up the search index rankings.

Sunbelt had discovered malicious sites connected with search terms such as "hospice", "cotton gin and its effect on slavery", "infinity" and many more. "You could be searching for really innocuous things and get nailed," said Mr Eckelberry. "There was really nasty stuff in there." "If there's any message from this I can scream from the rooftops its make sure you patch your machine," he said.

Security firm Trend Micro also discovered a series of booby-trapped sites aimed at Christmas gift shoppers and those looking for information about many other innocent subjects. "Some of the top rated hits are leading to the malicious sites," said Raimund Genes, chief technology officer at Trend Micro.

Mr Genes said the booby-trapped websites discovered by Trend Micro tried to exploit several different vulnerabilities in Microsoft's web browser. The sites also attempted to stop the malicious software being spotted by intermittently scrambling the package before it downloads.

He speculated that the campaign was being waged by the Russian Business Network - a hi-tech criminal gang known to favour web-based attacks. The booby-trapped websites were thought to be in operation for about 24 hours before Google began stripping them out of its search index. Some of the trapped websites are believed to be still turning up in searches carried out on Yahoo and MSN Live.

But, said Mr Eckelberry, this attack was likely to be a harbinger of many more.
"This is not going to go away," he said.

About Google
Google's mission is to organize the world's information and make it universally accessible and useful. As a first step to fulfilling that mission, Google's founders Larry Page and Sergey Brin developed a new approach to online search that took root in a Stanford University dorm room and quickly spread to information seekers around the globe. Google is now widely recognized as the world's largest search engine -- an easy-to-use free service that usually returns relevant results in a fraction of a second.

Website: www.google.com
Web Hosting News
138 New Tutorials available at DemoWolf
PayPal and MasterCard Are Now Partners
McAfee To Study Highlights URL Typos
WHMCS Billing Software for HostGater users
Grab your .ASIA domain now!
Increased Sales of .US Domains
Servecentric Announce Marketing and Sales Manager
Anniversary: 34sp.com – 7 Years as Leading Host
The Planet One of the Fastest Growing Companies in Texas
GoDaddy To Hold Premier Domain Auctions
 
HostColorEurope.com - Web Hosting
Featured Web Hosting Providers
Datacenter Luxembourg offers infrastructure, International Internet & Telco Connectivity, Managed E-Commerce, and Housing Services. Luxembourg offers many advantages for locating your Internet or Company Servers. Apart from excellent communications links, the country has recently adopted laws absolving the server operators from responsibility for the content of data stored on these servers, while securing this data on behalf of the owners.
Web Host Talk | Best Web Hosting | Canadian Hosting | Top Web Hosts | Business Web Hosting | Daw Hosting Blog | VPS Hosting
about us   | advertising   | submit provider   | webmaster   | contact