Google searches web's "dark side"

Viruses, hackers and crackers
Post Reply
Anthro
Moderator Emeritus
Posts: 5547
Joined: 21 Dec 2002, 02:00
Processor: i7 3770k
Motherboard: ASUS P8P67-Pro
Graphics card: 2xNvidia GTX670
Memory: 16 GB Gskill Sniper
Location: In SQL Space inserting 'null' on purpose
Contact:

Google searches web's "dark side"

Post by Anthro »

Source bbc.co.uk/news


One in 10 web pages scrutinised by search giant Google contained malicious code that could infect a user's PC.

Researchers from the firm surveyed billions of sites, subjecting 4.5 million pages to "in-depth analysis".

About 450,000 were capable of launching so-called "drive-by downloads", sites installs malicious code, such as spyware, without a user's knowledge.

A further 700,000 pages were thought to contain code that could compromise a user's computer, the team report.

To address the problem, the researchers say the company has "started an effort to identify all web pages on the internet that could be malicious".

Phantom sites

Drive-by downloads are an increasingly common way to infect a computer or steal sensitive information.

They usually consist of malicious programs that automatically install when a potential victim visits a booby-trapped website.

"To entice users to install malware, adversaries employ social engineering," wrote Google researcher Niels Provos and his colleagues in a paper titled The Ghost In The Browser.


"The user is presented with links that promise access to 'interesting' pages with explicit pornographic content, copyrighted software or media. A common example are sites that display thumbnails to adult videos."

The vast majority exploit vulnerabilities in Microsoft's Internet Explorer browser to install themselves.

Some downloads, such as those that alter bookmarks, install unwanted toolbars or change the start page of a browser, are an annoyance. But increasingly, criminals are using drive-bys to install keyloggers that steal login and password information.

Other pieces of malicious code hijack a computer turning it into a "bot", a remotely controlled PC.

Drive-by downloads represent a shift away from traditional methods of infecting a computer, such as spam and email attachments.

Attack plan

As well as characterising the scale of the problem on the net, the Google study analysed the main methods by which criminals inject malicious code on to innocent web pages.


It found that the code was often contained in those parts of the website not designed or controlled by the website owner, such as banner adverts and widgets.

Widgets are small programs that may, for example, display a calendar on a webpage or a web traffic counter. These are often downloaded form third party sites.

The rise of web 2.0 and user-generated content gave criminals other channels, or vectors, of attack, it found.

For example, postings in blogs and forums that contain links to images or other content could unwittingly infect a user.

The study also found that gangs were able to hijack web servers, effectively taking over and infecting all of the web pages hosted on the computer.

In a test, the researchers' computer was infected with 50 different pieces of malware by visiting a web page hosted on a hijacked server.

The firm is now in the process of mapping the malware threat.

Google, part of the StopBadware coalition, already warns users if they are about to visit a potentially harmful website, displaying a message that reads "this site may harm your computer" next to the search results.

"Marking pages with a label allows users to avoid exposure to such sites and results in fewer users being infected," the researchers wrote.

However, the task will not be easy, they say.

"Finding all the web-based infection vectors is a significant challenge and requires almost complete knowledge of the web as a whole," they wrote.
Temporary Absence
TheAlteredState
Registered User
Posts: 851
Joined: 04 Oct 2004, 02:00
Location: Kobol

Post by TheAlteredState »

Ooooh! Google is my friend! :D

They make good products too!

Google reminds me of Yoda.... not the PCF member :wink:
Significantly different from a normal waking beta wave state!
Vexo
Registered User
Posts: 435
Joined: 16 Nov 2006, 02:00
Location: Close... very close

Post by Vexo »

One in 10 web pages scrutinised by search giant Google contained malicious code that could infect a user's PC.
One in 10 web pages contains malicious code that could infect a user's PC. :D
Richard_
Registered User
Posts: 2295
Joined: 18 May 2003, 02:00
Location: Durban, South Africa

Post by Richard_ »

Vexo wrote:
One in 10 web pages scrutinised by search giant Google contained malicious code that could infect a user's PC.
One in 10 web pages contains malicious code that could infect a user's PC. :D
Makes you real happy, huh?
M1ke
Registered User
Posts: 1266
Joined: 13 Aug 2006, 02:00
Location: Cape Town
Contact:

Post by M1ke »

100% of people who click on those links are A) trying to find a crack,etc.
B) Illiterate
Last edited by M1ke on 13 May 2007, 07:55, edited 1 time in total.
"Science flies you to the moon. Religion flies you into buildings."
zerubabel
Registered User
Posts: 909
Joined: 08 Nov 2006, 02:00
Location: Durban

Post by zerubabel »

M1ke wrote:100% of people who click on those links are A) trying to find a crack,etc.
B) Illeterate
The irony is intense over here.
Fut Fut Fut Freestailo!
Moses
Registered User
Posts: 2545
Joined: 21 Jul 2004, 02:00
Location: Location:
Contact:

Post by Moses »

M1ke wrote:100% of people who click on those links are A) trying to find a crack,etc.
B) Illeterate
OMFG!

JFC!
Fishzn
Registered User
Posts: 2685
Joined: 19 May 2003, 02:00
Location: Durban
Contact:

Post by Fishzn »

M1ke wrote:100% of people who click on those links are A) trying to find a crack,etc.
B) Illeterate


ROFL, this has actually made me post again :P
"For what is a man profited, if he shall gain the whole world, and lose his own soul?"
NinjaTic
Registered User
Posts: 1218
Joined: 24 Feb 2003, 02:00
Contact:

Post by NinjaTic »

ROFLMAO :lol:
neon_chameleon wrote:

Im 22 next week and I cant commit to what Im going to eat for breakfast. I mean cereal is so boring but its quick, and eggs take forever to make and theres the toast to make sure you dont burn....
M1ke
Registered User
Posts: 1266
Joined: 13 Aug 2006, 02:00
Location: Cape Town
Contact:

Post by M1ke »

Oops. The irony lies thick... my bad.
"Science flies you to the moon. Religion flies you into buildings."
Post Reply