![]() |
|
Google搜寻网的暗边
星期一, 2007年5月14日
大约450,000是能发射所谓的“驾车下载”,安装恶意代码,例如spyware,不用用户的知识的站点。 另外700,000页被认为包含可能妥协用户的计算机的代码,队报告。 要论及问题,公司有“的研究员言在可能是恶意的”的互联网开始努力辨认所有网页。 幽灵站点 驾车下载是一个越来越共同的方式传染计算机或窃取高度机密信息。 他们通常包括自动地安装的恶意节目当一个潜在的受害者参观一个设陷井的网站时。 “诱惑用户安装malware,敌人使用社会工程学”,写Google研究员Niels Provos,并且他的同事在纸在浏览器题为鬼魂。 “用户出席以许诺对`兴趣的’页的通入以明确色情的美满,受著作权保护的软件或媒介的链接。 一个共同的例子是显示指图到成人录影的站点”。 大多数盘剥弱点在微软的安装自己的Internet Explorer浏览器。 有些下载,例如修改书签,安装不需要的工具栏或改变浏览器的起动页的那些,是心烦。 但越来越,罪犯使用驾车安装窃取注册和口令信息的keyloggers。 恶意代码其他片断劫持把它变成的计算机“bot”,一台遥远地受控个人计算机。 驾车下载代表一个转移从传染一台计算机传统方法,例如发送同样的消息到多个新闻组和电子邮件附件。 攻击计划 并且描绘问题的标度在网, Google研究分析了罪犯注射恶意代码到无辜的网页的主要方法。
它发现代码在网站所有者没设计或没控制的网站的那些部分经常包含了,例如横幅注意和装饰物。 Widgets are small programs that may, for example, display a calendar on a webpage or a web traffic counter. These are often downloaded from third-party sites. The rise of web 2.0 and user-generated content gave criminals other channels, or vectors, of attack, it found. For example, postings in blogs and forums that contain links to images or other content could unwittingly infect a user. The study also found that gangs were able to hijack web servers, effectively taking over and infecting all of the web pages hosted on the computer. In a test, the researchers’ computer was infected with 50 different pieces of malware by visiting a web page hosted on a hijacked server. The firm is now in the process of mapping the malware threat. Google, part of the StopBadware coalition, already warns users if they are about to visit a potentially harmful website, displaying a message that reads “this site may harm your computer” next to the search results. “Marking pages with a label allows users to avoid exposure to such sites and results in fewer users being infected,” the researchers wrote. However, the task will not be easy, they say. “Finding all the web-based infection vectors is a significant challenge and requires almost complete knowledge of the web as a whole,” they wrote. http://news.bbc.co.uk/1/hi/technology/6645895.stm?ls Have Your Say: Google searches web’s dark side Please read our posting guidelines before posting. Alternatively you can discuss this report here. Related News
|
Activists arrested because of UK Indymedia secret IP logging Last post by Mick @ 03:53 PM Go to Forum
| Latest Topics
Study takes step toward erasing bad memories Last post by Regina @ 02:53 PM Pirate Bay triumphant as prosecution drops half of charges Last post by Regina @ 02:51 PM Ex spy chief says government risks "police state" Last post by Nostalgia @ 02:22 PM Householders to be charged for each flush of toilet Last post by Victor @ 01:35 PM DNA left at crime scene could be used to create picture of criminal's FACE, say scien Last post by Nostalgia @ 01:24 PM UK mobile phone firms to sell data about customer activity Last post by Nostalgia @ 01:17 PM Nano Ink 'Tattoo' Could Monitor Diabetes Last post by Nostalgia @ 01:14 PM Can geo-engineering rebuild the planet? Last post by Nostalgia @ 01:08 PM Discussing a cashless society Last post by Nostalgia @ 12:18 PM Email This Page To A Friend Latest Headlines
More Breaking News Archive
|
The views expressed in the RINF news wire and newsletter are the sole responsibility of the author (s) and do not necessarily reflect the views of the webmaster. RINF.COM: Breaking News & Alternative Media is Copyleft - Copy & Distribute Freely. News Forum |