31 Mar 2008
A malware attack targeting search engine results is continuing to haunt several high-profile sites.
The attack uses the common cross-site scripting practice of embedding pages with small IFrame tags which redirect the user to a malicious page on a third-party site.
Researchers claimed that the latest attack is unique in that it targets search engine results.
The hackers have compromised search result pages, using search engine optimisation techniques to hijack search results and send users to sites which host malicious downloads.
Among the sites said to be compromised are major news outlets ABC, USAToday and Forbes, and retailers Wal-Mart, Target and Sears.
Security researcher Dancho Danchev said in a blog posting that the attacks have been lingering on the web for more than two weeks, despite efforts by Google to delete infected pages from its cache.
Danchev estimates that up to one million different search queries will lead users to the infected pages.
Administrators can protect against the attack by plugging the input validation vulnerabilities used to seed the malicious code within the pages.
But Danchev does not see the attacks slowing down anytime soon. "We are definitely going to see many other sites with high page ranks targeted by a single search engine results poisoning in combination with IFrame injections," he wrote.
Latest stories from Security
Related articles
Related jobs
Poll
What will be the biggest change to corporate technology in the future?
TFL director of Games transport Mark Evers discusses how the public transport network is preparing for this summer's event
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
Head of Compliance My client is currently seeking...
THis role is working for a multi national Financial organisation...
Professional Services Consultant - Data Protection, Backup...
Web Support Analyst (Drupal, Joomla or Wordpress, CMS...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?