Google warns drive-by downloads up 300 percent

Drive-by downloads, in which malicious Web sites exploit browser vulnerabilities to execute malicious code, have increased since April 2007, warned Google researchers have warned.

In April 2007, fewer than 0.4 percent of searches returned at least one harmful result. However, it increased to over 1.3 percent in January 2008, warned Google researcher Niels Provos in a Google blog post.

Drive-by downloads use URLs which target Web browser vulnerabilities to download and run malware automatically when a user visits the site.

Targeting Web browser vulnerabilities can circumvent some traditional security systems, such as firewalls.

Want to know more?

For all the latest news, analysis and opinion on security, click here

The Google researchers investigated billions of URLs over the past year and a half, and found more than three million unique URLs on over 180,000 Web sites automatically installing malware, said the blog post.

Web servers are targeted to host the malware. The researchers blamed poor patching of Apache and PHP servers for the amount of compromised sites. The Google researchers also wrote in a paper called All Your iFrames Point To Us that 67 percent of compromised servers and 64 percent of the Web sites that link to them are located in China.

"These results raise serious question about the security practices employed by Web site administrators," wrote the researchers.

According to a Google source, Google security researchers report compromised sites to StopBadware.org, a clearinghouse for Web malware research run by Harvard Law School, Oxford University, and technology companies including Google, Lenovo and Sun.

Google searches return all results, including suspect sites, to a user. However, Google uses the StopBadware.org list of compromised sites to place "interstitial pages" (pages that sit between the search results pages and the suspect page) between the user and the suspect site they wish to visit. Once the user has been warned that the site is probably compromised, they have the option to then click through to the site if they wish.

Like this article? Click below to send it to your mobile for free!

Advertisement

Talkback 0 comments


Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay MyPerfect.com.au has potential
    Victorian Web start-up My Perfect has a strong story and rationale for why it will succeed. But it has to overcome some challenges and design flaws first.
  • Array Storage infrastructure on the tender track
    For a large-scale storage project, it's not uncommon to go out to tender for the best deal — but when was the last time you had to put together a tender for a document management room?
  • Array Apple has killed the video store; will ISPs be next?
    The Olympics are nearly over, and the Australian team deserves kudos for an excellent performance all around. Yet even as the Olympic sun sets on the Bird's Nest for the last time this weekend, millions of spectators around the world will be scanning their dials in the hope of finding something else to fill their viewing hours.
  • More blogs »

Tags

Back to top

Featured