The Register® — Biting the hand that feeds IT

Feeds

Bing is the most heavily poisoned search engine, study says

Man, this Kool-Aid is chock full of payday loans

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Bing search results are more affected by poisoning than those of other search engines, according to a study by SophosLabs.

Search engine poisoning attacks are designed to skew results so that dodgy sites - anything from malware infected websites to payday loan sites - appear prominently in the index of sites related to popular search terms. In many cases the tactic is so successful that malware sites appear in the first page of results for popular search terms, in sometimes much higher than legitimate websites. More recently, miscreants have began trying to manipulate image search results.

SophosLabs blocks attempts to "redirect" surfers from search engines to dodgy sites and can therefore monitor the scale of search engine poisoning attacks. Two thirds (65 per cent) of the poisoned search results blocked by Sophos appliances over the last two weeks originated from Bing while 30 per cent came via Google. The other 5 per cent came via alternative search engines. The true state of play is probably even worse than these raw statistics suggest because Google is the most popular search engine, a factor not accounted for in these raw figures.

The vast majority of dodgy redirects (92 per cent) blocked by Sophos related to image searches. Only eight per cent related to text searches.

Search engines attempt to remove malicious sites from their indexes but this involves playing a game of cat and mouse in which the search engines are by no means always successful.

“Search engine poisoning can be very dangerous for internet users, as they trust the search engine they’re using to filter out malicious links, and in this case it seems to be Bing which is letting internet users down,” said Fraser Howard, principal virus researcher, Sophos. “All search engines will miss attempts to poison their search results however, and with very few give-away clues to spot infected image searches for example, the users themselves may also struggle to detect and avoid infected search results.”

Fraser compiled these figures after being asked to look into the use of search engine result poisoning in the promotion of payday loan outfits, an issue covered in a recent Daily Mirror article.

A run-down of Sophos' results (along with illustrated examples of search engine poisoning in action) can be found on the security firm's Naked Security blog here. ®

Agentless Backup is Not a Myth

It's hard to imagine that Bing users have any data worth stealing to be honest.

20
2

Stats fail aside he has a point

Many users still naively believe that "search" is supposed to find relevant pages related to your search term, quaint I know.

Unfortunately, when they search for common terms that marketing worms have used the ironically named "Search Engine Optimisation" on or worse google / bung have sold crapwords for the results are page after page of sponsored utter shite.

Try searching for "Product Name review" and you'll get Google Shopping (or the Bung equivalent), endless content copying scam sites (sorry, useful content aggregators who shouldn't all be bombed with agent orange), page after page of generic ecommerce sites with the product out of stock and zero reviews etc. etc. etc. Of course if you fall for the "Google shopping" most of those links will also be to content aggravators who are just another bloody pile of links to somebody, in some other country, who at some point in the past or future might have the product in stock for $3 plus $100,000,000 shipping.

Search engines ceased to be useful for many things quite some time ago, spotting the difference between the external "link poisoning" and that done by the search engine operator is rather hard.

18
2

the other 70% are what Google and Bing want you to see not what you are searching for

Words fail me to describe how stupid you just made yourself look. You've completely failed to understand the entire premise of a search engine.

20
9

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?