Hosting generously provided by
www.mv.com





Pick Your Language


SEO + Hacked Hosts Rig Google to Deliver Malware
Posted 1/29/08 by Robert from the hacking hosts for SEO department

"If last November you googled one of thousands of innocuous and common search terms, such as "Microsoft excel to access" or "how to teach your dogs to fetch," you were in line for an Internet attack that infects PCs with spam senders, password stealers, and other kinds of nasty malware.

Beginning on November 24 and continuing for less than a week, bad guys loaded up more than 40,000 Web pages with malicious software and thousands of common search terms. They then employed an automated network of malware-infected computers--known as a botnet--to link to those sites in blog-comment spam and other places. The mentions elevated the position of the poisoned sites in search results, often to the first page.

The malicious sites had no useful information. Instead, a simple click on a link to such a site in the search results was enough to launch attacks against your PC. If the attack found any of a number of vulnerabilities in a range of programs, it would load." - PCWorld

This is why I suspect search engines will move to a Digg based system (like wikipedia's beta search engine) and sole usage of algorithums for site placement less and less. Sure you can hire people in china/elsewhere to be your click monkey however this is much less effecient than simply utilizing SEO/blackhat SEO methods. Since we know this attack works it will continue to be used until it becomes a massive issue. This affects just about every search engine not just google so don't consider this a problem only google is dealing with. Consider this the first nail in the 'site algorithum only' coffin.

Article Link: http://www.pcworld.com/article/id,141796-c,onlinesecurity/article.html
Link to this Story: Blackhat SEO + Hacked Hosts Rig Google to Deliver Malware
Link: Have a Site Suggestion, Material Request, or News? Submit it!
News RSS Feed: Web Security news RSS Feed
Discuss this article    Find Related Stories



External Links:
Copyright 2000-2007 Cgisecurity.com.
Providing Web Security news since 2000.
Information contained on this website may not be copied without explicit permission.
Best Viewed with Netscape.
Website Security Web Application Security solid state drives ssd ebay ebay topdeals . buy macbook air not work safe software security


Popular Links By Subject

Sponsored Link (Advertise)


Subscribe to CGISecurity.com


The Web Security Mailing List
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] webapp security curse
  • [WEB SECURITY] FW: What's the Difference; PEN Testing and Black Box Testing?
  • RE: [WEB SECURITY] FW: What's the Difference; PEN Testing and Black Box Testing?
  • Re: [WEB SECURITY] FW: What's the Difference; PEN Testing and Black Box Testing?
  • Re: [WEB SECURITY] FW: What's the Difference; PEN Testing and Black Box Testing?
  • Re: [WEB SECURITY] FW: What's the Difference; PEN Testing and Black Box Testing?
  • [WEB SECURITY] Confirmed Program for SyScan'08 Hong Kong

  • Contact us
    Post News, get linkage!

    Name

    Email or Homepage:

    Subject

    Finish the word below: deadb33f

    Body