Feeds

Hackers re-poison Google search results

Tainted results punt scareware

Combat fraud and increase customer satisfaction

Hackers have responded to a purge of malicious links within search results by Google with a fresh effort to subvert the search giant's page rank system.

As previously reported, miscreants recently set out to poison search results with links to malware infested sites. The tactic involved gaming search engines' ranking systems by automatically posting links to malign sites in blog and forum posts. Hackers automated this link spamming process using networks of compromised zombie PCs.

Google cleaned up its search index earlier this week, but the original hackers (along with a new group) have responded with a fresh assault, reports anti-spyware firm Sunbelt Software.

Once again, plugging innocuous terms into Google, such as "funny drunk quote", can lead to search results where at least some point to malware. The tactic goes hand in hand with establishing thousands of pages on compromised servers that mention targeted terms to obtain a relatively high search engine ranking score.

Two gangs are involved in the latest wave of attacks. Both are trying to direct surfers onto malicious webpages hosted in China. One group is using the tactic to push Spy-shredder, a rogue anti-spyware program. Sunbelt reckons this group is made up of the same group of individuals that launched the original attack.

A second group is using the tactic to divert traffic to targeted sites, thereby generating illicit income through pay-per-click affiliate programmes.

Sunbelt has dissected the attack in a blog posting here. ®

SANS - Survey on application security programs

Whitepapers

Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.