黑客上海Google警告
2007年9月24日 · 由大衛布雷得里
亂砍了Google的索引,搜尋某些主題詞將培養將傳染您的個人計算機與malware或病毒的許多欺騙站點。 那是來自嗅有限公司研究Jenny Oliver博士今天叫的警告。
oliver博士是您的相當一般的衝浪者,消遣地搜尋最後星期天晚上,她點擊了什麼在只發現的SERPs似乎是一個合法的結果,一旦太晚,網站指向的結果懷有malware,并且這試圖傳染她的Mac。
「我不可能記住什麼我投入到查尋與」,她告訴了我, 「我無所事事地昨晚衝浪,我的Mac突然是非常繁忙的在幾秒鐘,好像安裝節目」。 她在那以後非常迅速重新了起動,但她的淨連接似乎不祥變得慢。
欺騙網站是在有一陣子附近,但搜尋一些非常具體,高級,關鍵詞組,在.cn頂級域(TLD)現在提出站點的一個無節制的數字在最近幾天內,一些80% Oliver博士的結果是被欺騙的頁。 增加「-站點:.cn」或「- cn」不完全根除了欺騙,或許,因為黑客莫名其妙地使用一個暗藏的漢字,看似空間在期間之前。
問題較詳細地現在被談論了 這裡. Oliver,然而,描述它如下: 「我設法再發現三欺騙在第一頁,使用主題詞我提及了[我們這裡不列出他們,為明顯的原因, db]甚而以-站點附文:.cn增加了,他們出現於SERPs的上面。 「避過「- .cn」它似乎spoofers使用一個非顯示的漢字,看似「asasdfdsf。 它出現作為空白或二在cn之前在地址的cn」換句話說。
站點有真正看標題,但看上去包含詞和詞組任意名單並且/或者被刮的內容從美國站點。 站點演講自己是被欺騙或偽造,如此對點擊他們是機警的,特別是如果您沒有充分的瀏覽器免役(Spybot S&D 為那), antispyware (Spybot和 AdAware),抗病毒(AVG)和到位防火牆(路由器或硬件和 ZoneAlarm).
喬 GoogleWatchdog 也報告相似的奇怪的行為。 “It appears that the faked sites are redirecting the Googlebot to a location where content can be indexed, while at the same time recognizing normal users and redirecting them to a site that includes the malware mentioned earlier. This is an obvious violation of Google’s guidelines, but the spammers have found ways to circumvent the rule and hide it from the Googlebot,” he says.
The possibility of cyberterrorism that exploits this Google looooophole are very alarming. All users could be threatened by activity as well as ecommerce sites and others. Until now, phishing attempts have usually been made to extort money from gullible surfers, clicking on malicious web addresses in their emails. This new attack on google search seems to represent a major shift in scale from random emails to the activity of the biggest search engine.
The bottom line for users? Don’t panic, just don’t click on .cn sites you find via google.com, for the time being. If you need to search across China, use google.cn instead. Thankfully, Google is now on the case, according to Matt Cutts. Indeed, searching for Dr Oliver’s problem keywords gives me “normal” SERPs. “However, the danger remains - hackers would be likely to use a time when defenses are low, like ‘out-of-hours’, surfing at these times should obviously be approached with extra caution,” she says.


















2 responses so far ↓
Jenny Oliver // Oct 5, 2007 at 8:20 am
This Google thing appears to be intensifying. I’ve now seen one entry hiding as a .txt file, and cached, to add to the ‘authenticity’. Altavista also appeared to be affected, but not so seriously. The Google watchdog (quoted above) had some interesting comments last night. A friend, upon entering his fairly distinctive surname, also found a faked page of the Guardian showing an article about his cousin!
Vigilance will help, but this is getting increasingly hazardous for new / naive users.
David Bradley // Nov 30, 2007 at 8:44 am
We published this news on September 24, and today I see that the BBC has finally caught up with the issue - http://news.bbc.co.uk/1/hi/technology/7118452.stm
Leave a Comment