Feeds

Google results flog millions of compromised webpages

Top billing

Choosing a cloud hosting partner with confidence

Two ongoing scams are tricking Google and other search engines into prominently displaying millions of compromised webpages that attempt to hijack end users' computers or steal their credit card numbers, researchers said.

One of the attacks is being used to direct people searching the web to an online store hawking pirated copies of popular software titles. Plugging the phrase "cheap vista for students" into Google, for instance, returned more than 19 million results, many of which redirected users to a site called soft4pcs.com.

A separate attack is the work of a botnet dubbed ASProx, which injects malicious links into misconfigured ASP webpages. Users who enter a wide array of search queries, such as "used corvette parts", received results pointing to a page that redirected to ads-t.ru, which attempted to serve a hostile Adobe Flash file that installs malware.

Gary Warner, director of research in computer forensics at the University of Alabama at Birmingham, said here that Google was returning more than 3.2 million results that contained the malicious script and Bing showed 188 million. Those numbers were significantly smaller when we tried the same search about 10 hours after the blog item was published.

The attacks highlight the intricate role search engines, websites, domain name registrars, and webhosts play in enabling campaigns that have the potential to scam large numbers of people. Most of the compromised webpages appeared to be hosted by legitimate websites with administrators who simply weren't careful enough. Stanford University, and the official websites for the Webby Awards and 1980s musician Bryan Adams, were just some of those complicit.

But attackers wouldn't bother compromising those pages if Google and other search engines didn't feature them prominently in their results. In a blog post published Thursday, researcher Denis Sinegubko lays out in painstaking detail how the software pirates were able to gin Google's system. If he can figure it out, so should Google and even its much smaller competitors.

"We don't comment on individual sites, but there is nothing particularly new going on here as far as I can tell," a Google spokesman wrote in an email to The Register. "I think it's important to keep in mind that search engines are a reflection of the content and information that is available on the Internet."

He went on to say that Google uses both algorithmic and manual techniques to detect such scams and removes entries when they're detected. But it's not unusual for the bad guys to find new ways to slip malicious pages into Google, he added, making for a never-ending game of cat and mouse.

Members of Microsoft's security team are actively working to remove the malicious links, according to one of them who asked not to be named because he wasn't authorized to speak to reporters. Among the actions taken, the team added ads-t.ru to a list of sites to flag, so results that contain that address should contain a warning as soon as Bing recrawls the pages.

Representatives of Yahoo didn't respond to emails seeking comment. ®

Remote control for virtualized desktops

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
BlackEnergy crimeware coursing through US control systems
US CERT says three flavours of control kit are under attack
prev story

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.
Website security in corporate America
Find out how you rank among other IT managers testing your website's vulnerabilities.