• On The Insider: Britney's Bikini-Clad Top 10
March 15, 2007 3:07 PM PDT

When phishers attack blog sites

by Robert Vamosi
  • Font size
  • Print
  • Post a comment
Phishers appear to be planting malicious exploit code on various sites in the hopes that you'll stumble upon them through keyword searches. Yesterday, security vendor Fortinet reported that certain Blogger.com sites appear to be hosting malicious content, and we speculated that the pages had been compromised using cross-site scripting attacks.

Today Google, which owns Blogger.com, said in a statement to CNET that the example sites cited by Fortinet appear to be "deliberately set up to promote phishing, which is against our terms of service."

Indeed, in reviewing the example we visited yesterday, there are numerous red flags. First, the content of the blog is gibberish. Although the page is in English, the visitor counter is in Russian. None of these alone are damning, but casual or even accidental visitors to the blog page could find themselves infected with a remote access Trojan horse. Google said that it is investigating these pages and concluded that "blogs found to include malicious code or promote phishing will be deleted."

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
advertisement

About Webware

Say No to boxed software! The future of applications is online delivery and access. Software is passé. Webware is the new way to get things done.

Add this feed to your online news reader

Webware topics

A CNET Conversation with Eric Schmidt

CNET's Tom Krazit and Molly Wood sit down with Google CEO Eric Schmidt to discuss the future of Android, the Chrome OS, the problem of real-time search indexing, and more.

Verizon tests sending RIAA copyright notices

The No. 2 phone company, known for its reluctance to intervene in antipiracy cases, strikes an agreement to forward copyright notices on behalf of the music industry.

Inside CNET News

Scroll Left Scroll Right