Share

Related Links

Related Stories

  • Comment: What’s your (SEO) poison?
    SEO poisoning is an increasingly popular method of attack for cybercriminals, and one that shows they are using more sophisticated techniques. In the last year, attackers have poisoned search results on everything from the MTV Video Music Awards to Google Wave invitations. Patrik Runald of Websense asks what makes these attacks such a success, and what does this mean for 2010?
  • Searching for Security
    With more than 30 000 web pages being compromised every day, search engine results could increasingly lead to malware infection. Kari Larsen asks what the search engines are doing to mitigate security threats, and how users can protect themselves
  • Rogue blogs pollute Google results
    Another round of SEO attacks has been discovered targeting Google. Criminals are crafting custom rogue blogs designed to target the 'long tail' of obscure Google searches to avoid having to compete with more popular searches in Google results, according to cyber intelligence company Cyveillance.
  • Google image search being infected by hackers
    There are signs that hackers are again turning to the recurring avenue of using attractive image files as a means to persuade internet users to infect their machines, through the usage of downloadable links to 'allow' users to view the files.
  • Imperva says hackers are tapping Google's powerful search engine features once again
    Data security specialist claims that cybercriminals are tapping the powerful search features that Google offers, generating more than 80,000 daily queries. This, the firm says, allows the hackers to conduct a significant amount of cyber reconnaissance at little of no cost to themselves.

Top 5 Stories

News

Google image search being infected by hackers

06 August 2010

There are signs that hackers are again turning to the recurring avenue of using attractive image files as a means to persuade internet users to infect their machines, through the usage of downloadable links to 'allow' users to view the files.

The problem first appeared late last year when video files of an adult or tabloid sensationalist nature were spammed out to internet users and, when the URL was clicked upon, the user was told to download a video codec to allow them to view the 'file'.

It now seems that the hackers have returned to this modus operandi, but enhancing it using Google image search to lure people in, and, when the URL is clicked through, the user is asked to update their Adobe PDF viewing software.

According to Webroot security researcher Andrew Brandt, he and a few colleagues discovered a number of rogue images of a US map that, when clicked upon, redirected web surfers to pages that "deliver an installer of a rogue antivirus in the security tool family of fine, fraudulent products."

"What really caught our interest was how the hack behaved, depending on the operating system and browser you used. With each different browser configuration, we were treated to one of several different, specially crafted malware delivery web pages", he said.

To test the extent of the hack, Brandt and his team "played around" with the manipulated search results using five different browsers with their default settings: Internet Explorer 6 and 8, Safari 5, Google Chrome, and Firefox.

"We then searched for USA Map and clicked the second result that appeared under the header 'Images for USA map' with all but the first image result that appeared on that first page of results linked to the malicious Web site", he said in his security blog.

The result of Webroot's research was a mixed bag, but the broad issue was the rogue images could end up infecting users, Infosecurity notes.

"The final piece of our research involved fiddling around with the Web domain to which all these manipulated search results link.

After sending a few dozen queries at the server, the server started pro-actively responding to the queries, which means, Infosecurity notes, that the hackers had coded their server at a sophisticated level.

This article is featured in:
Internet and Network Security • Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.