• The move to the new server is done. There are some software and database maintenance updates in process. This has us passing the hat around to help out. We appreciate any donations. Seriously, even a dollar helps. The payment page may be found here - https://www.audiokarma.org/support.html

Google Research Finds 10 Percent of Web Pages Hold Malware

Dr. Strangelove

Super Member
Banned
From today’s SANS NewsBites Vol. 9 Num. 39

TOP OF THE NEWS
--Google Research Finds 10 Percent of Web Pages Hold Malware
(May 11, 2007)
According to research from Google, 10 percent of web pages contain
malicious code. Google closely analyzed 4.5 million web pages over the
course of a year and found that approximately ten percent, or 450,000,
had the capability of installing malware without users' knowledge. An
additional 700,000 pages are believed to be infected with code that
could harm users' computers. The company says it has "started an effort
to identify all web pages in the Internet that could be malicious."
Most entice users to visit the dangerous pages through tempting offers,
and exploit holes in Microsoft Internet Explorer (IE) to install
themselves on users' computers. Google also examined the vectors used
by attackers to infect these web pages; most malicious code was located
in elements beyond the control of website owners, such as banner
advertisements and widgets
.
http://news.bbc.co.uk/2/hi/technology/6645895.stm
http://www.usenix.org/events/hotbots07/tech/full_papers/provos/provos.pdf
[Editor's Note (Skoudis): This is a very good piece of research, and
contributes significantly to our understanding the malware threat
better. I recommend that you read it. Also, it shows that today's
Internet is a cesspool of malware. Using mainstream browsers with
patches that often follow weeks after exploits are in the wild is an
increasingly dangerous proposition.]


Doc


From SANS NewsBites Vol. 9 Num. 40 (5/18/2007, this correction was posted:

Regarding the story we ran in the last edition of NewsBites about
Google's Web-Based Malware study: The researchers identified 450,000
URLs launching drive-by downloads from a set of 4.5 million, which in
turn had been culled from a larger set of 7 billion URLs, giving a much
lower rate of malware incidence than we indicated. We regret any
confusion this may have caused.
 
Last edited:
Register to hide this ad
Thanks, for posting this, Doc. I do appreciate all that you do to help us keep our computers safe and running well.

Much appreciated.
 
I am typically very, VERY selective when I hit a Google link. I have had one occurrence (um...so far) where an attempt was made to install malware and it was thankfully stopped at the gates by both Firewall and Virus protection.
 
There are a few simple things you could/should do to protect your computer and privacy on the net.
- Always login as a "user", not as "admin" or "root".
- Always make sure your OS and all your programs are patched and up to date.
- Always use a firewall.
- Always use a anti-virus/anti-spyware program.

Just a few tips from a guy that thinks he knows something about computers and security. :scratch2:
 
Well, we can go back as far as 2005 for info on why one browser was no better than another. Still, these newsbites are only to raise awareness, not be a podium for which environment is better than another.

Doc

WORMS, ACTIVE EXPLOITS, VULNERABILITIES, AND PATCHES
--Fixes Not Yet Available for Firefox Vulnerabilities
(9 May 2005)
Two vulnerabilities in the Firefox web browser could allow attackers to
gain control of users' computers just by getting them to visit a
maliciously crafted web site. Mozilla is recommending that Firefox
users disable Javascript or lock down the browser to prevent it from
installing additional software. There is no a patch available, although
information about the vulnerabilities and proof-of-concept exploit code
have already been released. Mozilla plans to release an update, Firefox
1.0.4, as soon as possible.
http://informationweek.com/story/showArticle.jhtml?articleID=163100338
http://www.vnunet.com/news/1162904
[Editor's Note (Schultz): The number of vulnerabilities in Firefox
recently has been alarming. At first Firefox appeared to be an
attractive alternative to Internet Explorer (IE) for security reasons,
but IE is now looking better and better in comparison.

(Shpantzer): There's so much hacking at the application layer, at some
point we'll have to actually lock down configurations for all browsers,
regardless of the security mythology that surrounds the project's code
and architecture. If you have a supposedly 'secure' browser that's
insecurely configured, well, it's not very secure.]
 
Yes, of course you are right about that. I did not intend to start any kind of flame war pro/con any system and have now deleted the OS/browser part from my previous post. I think however that the other tips are valid on most systems and are good guidelines to follow.
 
McAfee has a free program called Site Advisor www.siteadvisor.com that works with Firefox and IE. When you go to Google and get results from your search, little checkmarks and X's will then appear after each result, showing whether the site has adware and spyware added to downloads, how many emails a month you'd get if you gave them an email address, and how the particular site links to other sites as far as safety/annoyance issues go. Well worth looking at.
Tom
 
FWIW, I was a long time user of Netscape, which always seemed to fair much better than IE in not becoming compromised, but still had it's issues with Java scripting (akin to ActiveX in IE.)

I've found that migrating to Firefox and using the free NoScript add-on has made surfing the net a whole lot easier. With NoScript, you decide whether to allow a site to run Java script routines embedded in their web pages. It's been interesting to browse to various sites and have NoScript show that beside merely looking at the information on a web page, there are also connections attempting to be made to things like Double-Click, Google-Analytics, and a variety of other info gathering / info sharing entities. With NoScript, you can easily allow the main site to load while denying the other connections by default.

The other application I've found that complements Firefox and NoScript has been CounterSpy, which not only scans for malware/spyware/keyloggers, etc but actively prevents software from attempting to inject stuff into your registry and browser while you're browsing on-line.
 
Back
Top Bottom