Please fill in the field below to receive your profile link.
ADVERTISEMENT
Hackers step up search results attack
Big-name sites compromised in IFrame redirect scam
Shaun Nichols in California, vnunet.com31 Mar 2008
ADVERTISEMENT
A malware attack targeting search engine results is continuing to haunt
several high-profile sites.
The attack uses the common cross-site scripting practice of embedding pages
with small IFrame tags which redirect the user to a malicious page on a
third-party site.
Researchers claimed that the latest attack is unique in that it targets
search engine results.
The hackers have compromised search result pages, using search engine
optimisation techniques to hijack search results and send users to sites which
host malicious downloads.
Among the sites said to be compromised are major news outlets ABC, USAToday
and Forbes, and retailers Wal-Mart, Target and Sears.
Security researcher Dancho Danchev said in a
blog
posting that the attacks have been lingering on the web for more than two
weeks, despite efforts by Google to delete infected pages from its cache.
Danchev estimates that up to one million different search queries will lead
users to the infected pages.
Administrators can protect against the attack by plugging the input
validation vulnerabilities used to seed the malicious code within the pages.
But Danchev does not see the attacks slowing down anytime soon. "We are
definitely going to see many other sites with high page ranks targeted by a
single search engine results poisoning in combination with IFrame injections,"
he wrote.
West Midlands, Warwickshire, United Kingdom | Latham
System Tester/Test Analyst £27K-£32K + bonus, flexitime, 35 hour week, South Warwickshire, West Midlands. System Tester, Test Analyst, Systems Tester. Large financial services company looking for proven Testers and Test Analysts. Do you have at least ... more >
Network and Systems Engineers Working for MI5 you will use your expertise to protect the UK from terrorism, espionage and other threats to national security. You'll be joining a team that provides essential technical analysis ... more >
Hove, United Kingdom | Brighton & Hove City Council
Assistant Director / Head of ICT, c£75k plus relocation, Hove Technology has a huge part to play in people's lives. It empowers them, supports them, sets them free and makes their lives easier in a million ... more >
Colindale (C1905), United Kingdom | NHS Blood and Transplant
Operations Engineer, £28,313 - £37,326 pa plus High Cost Area Supplement, Colindale (C1905) About us The National Blood Service is an integral and vital part of the NHS. Our two million volunteer donors contribute 1.6 ... more >More job opportunities