• On TV.com: 5 SCARIEST Episodes in TV History
June 19, 2007 1:37 PM PDT

Dangerous Web sites, strings attached

by Robert Vamosi
  • Font size
  • Print
  • Post a comment
Share

As the automated Mpack attack continues to turn thousands of legitimate Web sites into compromised sites offering drive-by downloads of malicious software, security researcher Roger Thompson over at Exploit Prevention Labs reminds us there are other exploits compromising legitimate sites, and some are as easy to find as entering a simple search string on Google. For more than a week (starting before the current Mpack attack), Thompson has been posting a list of dangerous search strings on his blog site. I've collected these and indicated in parentheses some of the known exploits associated.

  • atlas mountains country (WebAttacker 2 or MPack)
  • rotweiller rescue
  • North Padre Island (WebAttacker 2 or Mpack)
  • arches national park (WebAttacker 2 or MPack)
  • canyonlands national park
  • mass lottery
  • air disasters in Florida (WebAttacker 2)
  • cd key windows xp profesional
  • batmobile for sale
  • victoria's secret (fake codec)
  • pokemon ruby gamesharks
  • blue book (mdac exploit)
  • IBM stock
  • pallet fire
  • Nigerian economic and financial crimes
  • who's a rat

Exploit Prevention Labs makes LinkScanner, a browser plug-in that will identify and block known exploits on tainted sites before you download the page. There are other safe surfing tools available as well; some are free.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
advertisement

The yogurt makers of tech: Gadgets to avoid

Don't buy these one-trick ponies--unless you like gizmos that gather dust.

Google wants to unclog Net's DNS plumbing

The Net giant, ever eager for a faster Internet, debuts its Google Public DNS service. With it, Google could become even more central to the Net.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
Click Here
advertisement

Inside CNET News

Scroll Left Scroll Right