May 15, 2007 1:38 PM PDT

Google finds malware on 1 in 10 Web sites

by Robert Vamosi
  • Font size
  • Print
  • 2 comments

In a paper (PDF) presented at last month's HotBots 2007 conference, researchers from Google say they've found malware downloads lurking on 1 out of every 10 Web sites visited. For this study Google analyzed 4.5 million URLs. The researchers determined that 450,000 of these contained some form of malicious code. The researchers identified four methods used to infect the unsuspecting Internet surfer. One is site-based, such as compromises in Web server security, but the others involve common user activity such as downloading user-contributed content, clicking Web advertising, and installing third-party widgets.

Attacking Web servers can be done with just an Internet browser. By appending carefully formed JavaScript onto vulnerable Web URLs, criminal hackers can inject malicious code onto the desktops of all future visitors to that site. Recent flaws in QuickTime and other media files allow attackers to use user-contributed content, such as video or music downloads, to spread bad code. Recently, Exploit Prevention Labs sounded the alarm about attackers using Google AdSense advertising to spread malware. Finally, widgets are yet another vector.

The research authors do not proscribe a solution, rather they conclude that the code used to infect innocent computers changes rapidly, making a survey such as theirs hard to complete. Recently, CNET reviewed several browser companions that analyze and rate Web site search results, protecting you before you click.

Originally posted at News Blog
As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Add a Comment (Log in or register)
Code Error
by dope.smugglaz May 18, 2007 8:45 PM PDT
The desired way the code changes and the sites infected, it seems the Internet is becoming the Boogie-Woogie floor for those who want the things upside down. I have never been able to understand the use of malicious code. Does anyone pay these guys to do it? And if they do, what use is it to shutdown the gateway of information? Could anyone help me out here.
Reply to this comment
I don't think they really care
by dgc49 May 21, 2007 11:54 AM PDT
I figure that this criminals think that things will continue on despite thier activities and that they will continue to reap the profits of thier crimes. And you know, I suspect that they may be right. Those of us who really care just won't let the internet go down.
advertisement

About Webware

Say No to boxed software! The future of applications is online delivery and access. Software is passé. Webware is the new way to get things done.

Add this feed to your online news reader

Webware topics

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

Inside CNET News

Scroll Left Scroll Right