SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture >> Data Warehousing

Gumblar attacks on Google search results intensifies

Gumblar attacks on Google search results intensifies

By:  Robert McMillan  On: 18 May 2009 For: IDG News Service (San Francisco Bureau)(NA) Creator

A Web attack that peppers Google search results with malicious links has infected more than 3,000 Web sites and continues to grow

A new attack that peppers Google search results with malicious links is spreading quickly, the U.S. Computer Emergence Response Team warned on Monday.

The attack, which has intensified in recent days, can be found on several thousand legitimate Web sites, according to security experts. It targets known flaws in Adobe's software and uses them to install a malicious program on victims' machines, CERT said.

The program then steals FTP login credentials from victims and uses that information to spread further. It also hijacks the victim's browser, replacing Google search results with links chosen by the attackers. Reports of the attacks follows last week's systems crash that caused a widespread Google outage.

Security experts started tracking the attack in March, when it had infected several hundred Web sites, but in recent weeks the number of infected sites has jumped dramatically. The attack has been called Gumblar because at one point it used the Gumblar.cn domain, though on Monday it had switched to a different one.

Security vendor ScanSafe has counted more than 3,000 infected Web sites, up from around 800 just over a week ago.

That kind of continued growth is unusual, according to Mary Landesman, a senior security researcher with ScanSafe. Attackers have launched many widespread Web attacks over the past few years, but after a few months the total number of infected sites usually drops as Webmasters clean up their servers.

With Gumblar, more and more sites are now being infected. Landesman believes it's because Gumblar's creators have been good at obfuscating their attack code and making it harder to spot on infected sites. And because they've been stealing FTP login credentials, they've been able to use a few new tricks to get their software onto the sites.

"They're doing things like changing folder permissions … and leaving behind multiple ways that they can get back into the server," she said.

Spam trends for 2009:

What to look out for

Still, Web attacks have become so widespread that Gumblar remains a relatively small-scale phenomenon, according to Symantec Security Response Product Manager John Harrison. Last year, Symantec counted 18 million online attacks against its customers. With Gumblar, it has counted 10,000. "It's really just another day with drive-by downloads," he said. "There really are so many of these."


Sign up for our Newsletters












Print |  Views: 1267   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Robert McMillan Robert McMillan is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

How to not have your Web site hacked like Sony's
How to not have your Web site hacked like Sony'sA SQL injection attack was used to plant malicious code on pages of two popular Sony Playstation games - SingStar Pop and God of War, reports security company Sophos. Hundreds of Web pages from other businesses have also been compromised.
Malaysian capital has region’s highest number of infected PCs
Malaysian capital has region’s highest number of infected PCsA study by Symantec shows that Malaysia has become a prime target for cybercriminals to launch malicious attacks in Southeast Asia
Microsoft downplays malware warnings
Microsoft downplays malware warningsWith security vendors warning of new malware that exploits a recently patched flaw in Windows, Microsoft Corp. is saying that attacks are not on the rise.
Fortinet lists August’s most dangerous online threats
two viruses disguised as security software antivirus xp 2008 and xp security center have topped fortinet’s top 10 list of august’s most reported online threats. the sunnyvale, cali
blog comments powered by Disqus