Skip to navigation

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.

Latest News

Spammers exploiting Google flaw

Posted on 19 Mar 2008 at 11:50

Spammers are tricking users into downloading malware by exploiting a loophole in the way Google handles advertising links, claims McAfee.

The security company has observed spammers using open redirect links to send users to a third party page from a link that appears to point to Google's own website.

"At first we thought Google page ads were being used to conceal the actual URL and subvert traditional anti-spam detection techniques. However, it seems one can change the linked URL to point to any site of your choice - as no validation appears to be done on Google's end," says McAfee Avert Labs researcher, Vinoo Thomas, in a blog post.

The vulnerability works for files as well as sites, so spammers can link directly to an executable which will download directly to the user's computer.

"Although this type of technique is not necessarily new, the problem is that Google is not preventing the redirects to such sites. Google must be aware of this redirect abuse, and it's hard to understand why it doesn't prevent these redirects working for known bad file types or for spam and malware sites," says Vinoo.

Earlier this year a similar tactic was uncovered using Microsoft's SkyDrive service. Spammers were found to be using the service to host sites with a simple redirect to another page that hosts malware. By linking to SkyDrive in spam emails, messages were less likely to be caught by spam filters.

Google says it does close down the malicious redirects. "Malware is a problem for all internet users, not just Google users," says a Google spokesman. "We actively work to protect our users from this kind of activity. When we learn of these types of redirectors, we work to close them, as we are doing in this case."

Author: Matthew Sparkes

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

Most Commented News Stories
Latest Blog Posts Subscribe to our RSS Feeds
Latest Reviews Subscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2008