Spammers exploiting Google flaw
Posted on 19 Mar 2008 at 11:50
Spammers are tricking users into downloading malware by exploiting a loophole in the way Google handles advertising links, claims McAfee.
The security company has observed spammers using open redirect links to send users to a third party page from a link that appears to point to Google's own website.
"At first we thought Google page ads were being used to conceal the actual URL and subvert traditional anti-spam detection techniques. However, it seems one can change the linked URL to point to any site of your choice - as no validation appears to be done on Google's end," says McAfee Avert Labs researcher, Vinoo Thomas, in a blog post.
The vulnerability works for files as well as sites, so spammers can link directly to an executable which will download directly to the user's computer.
"Although this type of technique is not necessarily new, the problem is that Google is not preventing the redirects to such sites. Google must be aware of this redirect abuse, and it's hard to understand why it doesn't prevent these redirects working for known bad file types or for spam and malware sites," says Vinoo.
Earlier this year a similar tactic was uncovered using Microsoft's SkyDrive service. Spammers were found to be using the service to host sites with a simple redirect to another page that hosts malware. By linking to SkyDrive in spam emails, messages were less likely to be caught by spam filters.
Google says it does close down the malicious redirects. "Malware is a problem for all internet users, not just Google users," says a Google spokesman. "We actively work to protect our users from this kind of activity. When we learn of these types of redirectors, we work to close them, as we are doing in this case."
Author: Matthew Sparkes
advertisement
- Need a bit of extra Christmas cash? Grass up your boss, says BSA
- Photoshop Mobile on Android review: first look
- ATI Radeon HD 5970: 42% more expensive in the UK
- Office 2010 Beta – 32-bit or 64-bit – The Choice is Clear
- Why Britain's watchdogs have fewer teeth than goldfish
- Tabbed documents: how to make Office 2010 great
- Outlook 2010 People Pane – does it spell death to Xobni
- Microsoft Outlook 2010 screenshots
- Co-Authoring in Word 2010 and SharePoint Foundation 2010
- Microsoft Outlook 2010 screenshots: Backstage view
- Getting to grips with Microsoft's IT Health Environment Scanner
- Virtualise your servers
- The changing face of travel gadgets
- Build your own distributed file system
- The bulletproof Dell that costs an arm and a leg
- Microsoft Office 2010 Technical Preview: Q&A
- Lawnmowers, the TyTN II and one odd insurance request
- There'll never be a bulletproof OS
- How far can we trust apps?
- Five nice touches in Outlook 2010
advertisement
Printed from www.pcpro.co.uk


