• On The Insider: Holy Cleavage!
May 15, 2007 1:38 PM PDT

Google finds malware on 1 in 10 Web sites

Posted by Robert Vamosi
  • Font size
  • Print

In a paper (PDF) presented at last month's HotBots 2007 conference, researchers from Google say they've found malware downloads lurking on 1 out of every 10 Web sites visited. For this study Google analyzed 4.5 million URLs. The researchers determined that 450,000 of these contained some form of malicious code. The researchers identified four methods used to infect the unsuspecting Internet surfer. One is site-based, such as compromises in Web server security, but the others involve common user activity such as downloading user-contributed content, clicking Web advertising, and installing third-party widgets.

Attacking Web servers can be done with just an Internet browser. By appending carefully formed JavaScript onto vulnerable Web URLs, criminal hackers can inject malicious code onto the desktops of all future visitors to that site. Recent flaws in QuickTime and other media files allow attackers to use user-contributed content, such as video or music downloads, to spread bad code. Recently, Exploit Prevention Labs sounded the alarm about attackers using Google AdSense advertising to spread malware. Finally, widgets are yet another vector.

The research authors do not proscribe a solution, rather they conclude that the code used to infect innocent computers changes rapidly, making a survey such as theirs hard to complete. Recently, CNET reviewed several browser companions that analyze and rate Web site search results, protecting you before you click.

Originally posted at News Blog
As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from Webware
Googlepedia for Firefox brings Wikipedia to you
Tiltshiftmaker turns photos into miniature scenes
Resumator makes hiring collaborative, paper-free
LG Blu-ray players stream Netflix, CinemaNow, and YouTube
Tech layoffs: The scorecard
Opera's new SDK: Better browsing on the Wii?
Daily Tidbits: GrandCentral making its way to...Spain?
Zuckerberg: New year, 150 million Facebook users
Add a Comment (Log in or register) 2 comments
Code Error
by dope.smugglaz May 18, 2007 8:45 PM PDT
The desired way the code changes and the sites infected, it seems the Internet is becoming the Boogie-Woogie floor for those who want the things upside down. I have never been able to understand the use of malicious code. Does anyone pay these guys to do it? And if they do, what use is it to shutdown the gateway of information? Could anyone help me out here.
Reply to this comment
I don't think they really care
by dgc49 May 21, 2007 11:54 AM PDT
I figure that this criminals think that things will continue on despite thier activities and that they will continue to reap the profits of thier crimes. And you know, I suspect that they may be right. Those of us who really care just won't let the internet go down.
advertisement

About Webware

Say No to boxed software! The future of applications is online delivery and access. Software is passé. Webware is the new way to get things done.

Add this feed to your online news reader

Webware topics

In the news now

Apple: DRM-free tunes, unibody MacBook Pro

roundup At Macworld, Phil Schiller touts 10 million songs sans DRM, plus 69-cent songs, a unibody 17-inch notebook, iLife updates, and more.


Countdown to CES

special coverage The tech community descends on Las Vegas as the Consumer Electronics Show gets ready to kick off in all its gadgety glory.


advertisement

Inside CNET News

Scroll Left Scroll Right
-->