Web Hosting Vodahost    

Home Take The Royal Tour! Order Now Features Prices
Go Back   Web Hosting > Search Engines & Directories > Google

Notices

Google Discussions and articles relating to all that is Google, including AdSense, Adwords, API’s, Sitemaps, Google Analytics, Froogle, etc…

Closed Thread
 
Thread Tools
  #1  
Old 06-14-2007, 08:47 PM
LadyEye's Avatar
General & Forum Moderator
 
Join Date: Jun 2006
Location: Canada
Posts: 10,617
Send a message via MSN to LadyEye
Default Booby Traps Hide in Google Sponsored Links

http://blogs.pcworld.com/staffblog/archives/004213.html

Roger Thompson of Exploit Security Labs posted today about finding poisoned Google sponsored links that surreptitiously direct searchers through malicious sites that attempt to surreptitiously install malware on your PC.
According to Thompson, if you ran a Google search for "BetterBusinessBureau" from April 10 through about 11am EST this morning, you'd have stood a one in three chance of seeing a top sponsored link with green link text that read www.bbb.org - just like the real search result. If you clicked that sponsored link, you'd even end up at the regular BBB site as per normal.
But before you got to the bbb.org site, you'd invisibly pass through a malicious site that would try to exploit an Internet Explorer browser hole. The site wouldn't have shown up in your browser, and you wouldn't have had any way of knowing about the redirection ahead of time. Unlike with real search results, you don't see the destination URL if you pass your mouse over a Google sponsored link.
Our colleagues over at InfoWorld have some more background on this in a story called: Experts: Google Doesn't Police Advertisers.

You'd have had no idea that you passed through the poisoned site on your way to the BBB - or that if your PC lacked a critical security patch, the site would have surreptitiously downloaded malware onto your computer meant to steal banking credentials. (When Thompson e-mailed a sample to me, my antivirus identified it as Infostealer.Bancos and deleted it from my e-mail.)
I haven't yet heard back from Google to see if they can verify these attacks, but Thompson has screen shots with results from his LinkScanner browser add-on that appear to identify the malicious links.
When I talked with Thompson, he said the attacks attempted to hit an old, but still commonly attacked Windows MDAC vulnerability in Windows XP and Windows Server 2003. So if you were smart enough to keep your system patched you'd have been safe from these particular exploits.
But it looks like the framework is still in place for other Internet criminals to come along and pay for a similar sponsored link for other search results. It's not unusual to redirect through an advertising service site that records your passing for legit sponsored links, Thompson says. When I just checked, Ask.com also hides the URL for sponsored links, while Yahoo and MSN display what looks like redirection links at yahoo.com and msn.com.
Also, a subdirectory of the malicious redirection site used in the Google attacks still appears to host the MDAC exploit.
I'd love to hear from Google whether they screen purchasers of sponsored links or the redirection URLs they use. I hope so, since after this and the MySpace malicious banner ad fiasco from last year, online crooks now seem to happily use ads as an attack vector.

In the meantime, you can use XPL's Linkscanner and McAfee's SiteAdvisor, both available in free versions, to give you some advanced warning about dangerous search results.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #2  
Old 06-15-2007, 11:02 AM
Corporal
 
Join Date: Feb 2007
Posts: 13
Thumbs up Re: Booby Traps Hide in Google Sponsored Links

Interesting article, thanks. will pass this onto a friend who had details stolen recently & couldn't work out how it was done

Personally I completley avoid it....Linux & Firefox ;)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #3  
Old 09-11-2007, 03:47 PM
Second Lieutenant
 
Join Date: Aug 2007
Posts: 99
Default Re: Booby Traps Hide in Google Sponsored Links

no way??? although i keep my computer updated i am never clicking on a goolle ad ever again!

bluerovers
www.bluerovers.co.nz
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #4  
Old 09-16-2007, 01:40 PM
First Sergeant
 
Join Date: Jun 2007
Posts: 71
Default Re: Booby Traps Hide in Google Sponsored Links

Thanks Ladyeye, is there nothing these scumbags will stop at? I guess not where money is concerned. The internet makes Dodge City look like a nunnery. LOL
__________________
Ian
For custom web graphics ebook covers headers and free buttons.
imagewizard.biz
Look younger with Facialwizard
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #5  
Old 10-21-2008, 01:30 AM
Vasili's Avatar
General & Forum Moderator
 
Join Date: Mar 2006
Posts: 10,939
Lightbulb Re: Booby Traps Hide in Google Sponsored Links

Unlike other Anti-Virus or Internet Security utilities, ca Anti-Virus 2008 includes Website Verification tools and Link Validators as standard to protect from re-directs and ghosted applications.

VISTA once proclaimed it would have such protection included, but don't count on it. Same thing for the VeriSgn and Yahoo's "validated link" programs and how they tried to get all the browsers to adopt the practice (they discovered they would effectively limit their advertiser pool by about 30% if they implemented such a plan and departed from their hands-off "surfer beware" position). It's all about the money, unfortunately, and Google is the worst offender of all time.

Download a FreeTrial of CA Anti-Virus 2008 Here
__________________
Choice Pro SEO
Choice Pro Webs
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off



All times are GMT +1. The time now is 09:47 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC7
2005-2009 VodaHost Web Hosting Your Perfect Web Host - All Rights Reserved

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203