.
/v3-uk/news/1972934/worm-creates-fake-google-site
19 Sep 2005, Robert Jaques , V3
Security firm Panda Labs has detected a worm which attempts to spoof Google. P2Load.A spreads via P2P networks using the file-sharing programs Shareaza and Imesh.
The worm copies itself to the shared directory of these programs as an executable file called 'Knights of the Old Republic 2', referring to a computer game related to the Star Wars saga.
When P2Load.A is run, it displays an error message informing the user that a file does not exist and offers it for download. The download modifies the user's start page, showing advertising and spoofing the identity of Google.
To do this, the worm modifies the HOSTS file on the computer so that when users try to access Google, they are redirected to a page hosted on a server in Germany that looks exactly the same as Google, but is not controlled by the search giant.
The page is an exact copy of Google and redirects users even if they make a mistake when entering the address - such as 'wwwgoogle.com', 'www.gogle.com' or 'www.googel.com' - leaving users unaware of the change.
When users run a search, the results are shown correctly or with slight variations in the order in which they would be shown in Google. However, the sponsored links, which are usually shown at the top of the search results and correspond to companies that pay for this service, are different.
For certain searches, other links appear which have been specified by the creator of this malware, resulting in increased traffic to these websites.
"The creator of this worm has taken advantage of the importance of a company appearing among the first few links in the search results of an internet browser," said Luis Corrons, director of Panda Labs.
"Its aims are to increase visits to the pages linked by the creator of this malware, or to earn an income from companies that want to appear in the first few results in computer where the identity of Google has been spoofed.
"In both cases, the motivation of the author of this malware is purely financial."
Do you agree?
fake google
It makes you wonder about google and who they really are! Bottom line this is a crime but even more important is how it shows what is really going on in the intelligence domains ... hidden ... treasonous and tyranical.
Posted by bob, 19 Sep 2005
Don't pick on google
Google is a great service, and it seems like it would be pretty easy to sucker software pirates into opening a fake version of google. This could happen to ANY site out there...
Posted by Jon, 20 Sep 2005
makes you wonder
Doesn't it make you wonder if the record and movie companies are writing spyware and dumping it on the p2p sharing networks?
Posted by Scott Hendison, 20 Sep 2005
Alternative Google Site
The previous post would have you believe that Google is behind the mis-direction, yet Google seems to be 'out of the loop' so to speak. Their problem is to deny the person using the mis-spelt domain names from profiting from their lack of foresight. They should have done this long ago, to stop the problem in advance. Their mistake, they should pay for it.
Posted by Kevin, 20 Sep 2005
@kevin
its not because google didn't buy these domain names its because the worm modified the HOSTS file (which acts a local dns lookup), so even google.com goes to the worm's page. It's just mean enough to also catch the typo and reroute their dns to its malware page. Google has nothing to do with it, it could have been microsoft as easily. All you need it map the IP to the domain name and you can reach yahoo's site typing google.com
Posted by san, 08 Jun 2006