PDA

View Full Version : Google results poisoned with malicious links


Tony
21st May 2009, 02:28 PM
Google results poisoned with malicious links
Security threat found on legitimate websites

Robert McMillan

A new attack that peppers Google search results with malicious links is spreading quickly, the US Computer Emergence Response Team has warned.

The attack, which has intensified in recent days, can be found on several thousand legitimate websites, according to security experts. It targets known flaws in Adobe's software and uses them to install a malicious program on victims' machines, CERT said.

The program then steals FTP login credentials from victims and uses that information to spread further. It also hijacks the victim's browser, replacing Google search results with links chosen by the attackers.

Security experts started tracking the attack in March, when it had infected several hundred websites, but in recent weeks the number of infected sites has jumped dramatically. The attack has been called Gumblar because at one point it used the Gumblar.cn domain, though on Monday it had switched to a different one.

Security vendor ScanSafe has counted more than 3,000 infected websites, up from around 800 just over a week ago.

That kind of continued growth is unusual, according to Mary Landesman, a senior security researcher with ScanSafe. Attackers have launched many widespread web attacks over the past few years, but after a few months the total number of infected sites usually drops as webmasters clean up their servers.

With Gumblar, more and more sites are now being infected. Landesman believes it's because Gumblar's creators have been good at obfuscating their attack code and making it harder to spot on infected sites. And because they've been stealing FTP login credentials, they've been able to use a few new tricks to get their software onto the sites. "They're doing things like changing folder permissions … and leaving behind multiple ways that they can get back into the server," she said.

Still, web attacks have become so widespread that Gumblar remains a relatively small-scale phenomenon, according to Symantec Security Response Product Manager John Harrison. Last year, Symantec counted 18 million online attacks against its customers. With Gumblar, it has counted 10,000. "It's really just another day with drive-by downloads," he said. "There really are so many of these."

Security experts say that if you're using a fully-patched system with up-to-date security software, you should be protected from these attacks. To date, they've worked by hitting the victim with malicious PDF or Flash files.

webslave
21st May 2009, 04:08 PM
Thanks for that Tony

DumpsterSlutsFan1980
21st May 2009, 08:16 PM
Thanks a bunch for the heads-up!

wanker125
21st May 2009, 11:21 PM
Acrobat reader 9.1, 8.1.4, and 7.1.1 are the most recent.
Foxit reader v3 build 1506, and v2.3 build 3902.

basicly make sure you update your stuff.

goldy fish
5th August 2009, 01:01 PM
Yes, without good protection on the Internet it is impossible

Orb
9th August 2009, 10:02 PM
Damnnnnnn so this is what's been screwing with me.. crap.. :| I guess I've got some cleansing I need to do and updates. Thanks Tony.

EDIT: Just noticed this is kinda old.. wonder if it's still out there because something's been redirecting me to different pages constantly.

Doctor_Gonzo
9th August 2009, 11:05 PM
I think there's a new wave of this crap. .

MacheteBetty
10th August 2009, 12:04 AM
Ohh fantastic.

wanker125
10th August 2009, 03:34 AM
just need to find a safe DNS server. no need to panic.
keep all security software updated, as well as plugins (pdf reader, flash, quicktime, etc) and the liklyhood of spoofed results is greatly reduced

H0rnnyy
12th August 2009, 03:05 AM
google = virus

Frenzy
18th November 2009, 08:21 AM
google = virus

I lol'd.


Google = Win.

Thanks for the info.