Computing in the real world
SEARCH FOR: IN:
Guest  Level 00    Register Log in

News 

[Security]
Wednesday 19th March 2008
Spammers exploiting Google flaw 12:06PM, Wednesday 19th March 2008
Spammers are tricking users into downloading malware by exploiting a loophole in the way Google handles advertising links, claims McAfee.

The security company has observed spammers using open redirect links to send users to a third party page from a link that appears to point to Google's own website.

"At first we thought Google page ads were being used to conceal the actual URL and subvert traditional anti-spam detection techniques. However, it seems one can change the linked URL to point to any site of your choice - as no validation appears to be done on Google's end," says McAfee Avert Labs researcher, Vinoo Thomas, in a blog post<
 
 
ADVERTISEMENT
.

The vulnerability works for files as well as sites, so spammers can link directly to an executable which will download directly to the user's computer.

"Although this type of technique is not necessarily new, the problem is that Google is not preventing the redirects to such sites. Google must be aware of this redirect abuse, and it's hard to understand why it doesn't prevent these redirects working for known bad file types or for spam and malware sites," says Vinoo.

Earlier this year a similar tactic was uncovered using Microsoft's SkyDrive service. Spammers were found to be using the service to host sites with a simple redirect to another page that hosts malware. By linking to SkyDrive in spam emails, messages were less likely to be caught by spam filters.

Google says it does close down the malicious redirects. "Malware is a problem for all internet users, not just Google users," says a Google spokesman. "We actively work to protect our users from this kind of activity. When we learn of these types of redirectors, we work to close them, as we are doing in this case."

Submit to: Digg  |  Slashdot  |  Del.icio.us  |  Technorati

Related News


SYMANTEC Norton Ghost - ( v. 14.0 ) - complete pa
Norton Ghost 14.0 backs up and restores a user's entire PC computer system, including all of its data - applications, settings, folders and files - and offers exclusive remote backup management, ...
SYSTRAN SYSTRAN Office Translator 2007 English-Eu
SYSTRAN Office Translator is the perfect translation software product for Microsoft Office users. It uses the same robust translation engine selected by Google, Yahoo!, global corporations, and t...

SYMANTEC Norton Ghost - ( v. 14.0 ) - complete pa
Norton Ghost 14.0 backs up and restores a user's entire PC computer system, including all of its data - applications, settings, folders and files - and offers exclusive remote backup management, ...
pc world business
SYSTRAN SYSTRAN Office Translator 2007 English-Eu
SYSTRAN Office Translator is the perfect translation software product for Microsoft Office users. It uses the same robust translation engine selected by Google, Yahoo!, global corporations, and t...
micro warehouse
Compare Broadband
Broadband?
Compare 50+ packages
Enter your postcode below:
Powered by:
Top 10 Broadband
Bookstore Top 5

Columns

Prolog:

There are lots of ways to save money, says Tim Danton, but it's the little things that count. › See full Opinion