PDA

View Full Version : Spyware Changes Google Results


! !
06-28-2004, 07:24 PM
http://zdnet.com.com/2102-1104_2-5250383.html?tag=printthis

Extreme popularity brings an albatross of preditors - wishing to cash in on your success.

Gloggle.Shing has been identified as SPYWARE that is surreptitiously downloaded to the computers of unknowing surfers - who have the misfortune of visiting the wrong site. :eek:

This software among others, can modify the SERPs that an infected computer will bring up while searching Google among several other sites."

Google in particular has drawn the attention of interlopers. Researchers for Lavasoft, which sells the popular spyware detection software Ad-aware, have identified one application that targets Google by altering the display of search results. The spyware, known as "Gloggle.Shing," carries a high threat level, according to Lavasoft, because the software installs itself in stealth mode when people visit certain Web sites, which the company did not name.

! !
07-30-2004, 11:50 AM
http://news.zdnet.co.uk/internet/security/0,39020375,39162176,00.htm

Google's ability to record Internet sites' content can be used to pinpoint those with weak security, Johnny Long, a security researcher and computer scientist for Computer Security Corp. told attendees at the Black Hat Security Briefings here. Though the technique is not new, well-crafted searches turned up so many sites with vulnerabilities that even jaded researchers laughed during the session.


:eek: :eek: :eek:

By searching for default server page titles, for example, an attacker can find easily exploitable servers. Applications left in default modes can also be found by searching for error pages generated by the software. And searching for specific file names can pinpoint vulnerable servers connected to the Internet.


___________________________

http://www.winnetmag.com/Article/ArticleID/43375/Windows_43375.html

http://www.foundstone.com/index.htm?subnav=resources/navigation.htm&subcontent=/resources/proddesc/sitedigger.htm

http://www.infosecwriters.com/text_resources/doc/Demystifying_Google_Hacks.doc

The paper outlines several ways in which someone can use a particular search syntax in Google to query for sites that might have known vulnerabilities. For example, Google supports query syntax that includes the commands intitle:, inurl:, allinurl:, filetype:, intext:, and more. Google isn't the only search engine that provides the use of this sort of query syntax. MSN Search, AlltheWeb, Yahoo!, and others support a similar syntax to varying degrees