Malicious code on Google?
July 14, 2006
Websense Security Labs said it has found thousands of pieces of malicious code available on the Internet. The security firm searched Google with its's own application programming interface (API) and found many malicious executable files indexed by the search engine.
A Google search for 'Signature 00004550' results in numerous links to dangerous executable files. The reason this search works is because when Google indexes the executable file, it passes the PE file format of the windows executable.
'This does look concerning, but you have to know exactly what you're looking for in order to find such code,' said Websense technical director Mark Murtagh.
The malicious code is mostly posted in newsgroups with false names that would normally trick a user. Websense also found some on forum sites, as well as regular personal, educational, compromised and underground sites. Several pieces of spyware were found on poker and casino sites.
The discovery is likely to open up the debate on open-sourcing. Although this is a useful tool for security experts to discover malicious code online, it is also there for malcode authors to use.
'Criminals generally work quicker and are faster to respond to malcode being published online. Full disclosure on day 1 only helps the attacker,' said McAfee security analyst Greg Day.
But Richard Starnes, president of the Information Systems Security Association disagrees. 'Trying to regulate content on the Internet is very much a losing battle. If it's there, people can pull it off, write signatures and then know if they are under attack or not,' he said.
Become an authorized reseller of Proxy Sentinel™ and Firewall Sentinel™. Do like the rest of our authorized resellers and have your clients benefit the important security features of our products and solutions, while increasing your sales at the same time. Click here for all the details.
You can link to the
Internet Security web site as
much as you like. Read our section on how your company can participate in our
reciprocal link exchange program
and increase your rankings
in the major search engines such as
Site optimized by Pagina+™
Powered by Sun Hosting
Search engine keywords by Rank for Sales
Development platform by My Web Services
Internet Security.ca is listed in
Global Business Listing