Posted on 12/08/2007 12:32:29 PM PST by Swordmaker
Over a year after first coming to light, the cache engines of major search engines are still providing a safe hiding place for malicious code, a security company has revealed.
The latest warning comes from security company Aladdin, which logged an attack against a university Web site which was eventually traced back to just such a 'poisoned cache.' The originating site had been taken offline, but the code from it was still able to spread by living on in the caches of a major search engine.
To make matters worse, cached malicious code could circumvent URL filtering systems because they would only stop the original site URL and not the site as found via a search engine indexing it from cache.
Aladdin didn't specify the engine involved in the incident, but did say the problem affected Google, MSN Live and Yahoo. According to Aladdin's Ofer Elzam, cached pages could remain active for weeks and possibly even months, and would remain in their original state until the cache algorithm refreshed its store.
"As I see it, they [search engines] have done nothing to solve it," he said of the problem. "It is they who are infecting the users. Do they feel responsible?"
This type of cache poisoning was first noticed around four years ago, with Israeli security company Finjan claiming last year that it was also to some extent affecting ISP and enterprise caching systems.
"This is more than just a theoretical danger. It is possible that storage and caching servers could unintentionally become the largest 'legitimate' storage venue for malicious code," said Finjan's CTO Yuval Ben-Itzhak said at the time. "Almost every malicious Web site out there has a copy on a caching server."
The attack documented by Aladdin involved a nest of inter-linked Web sites, and a swarm of over a hundred Trojans, of which 51 were not detectable by signature-based scanning products. Advanced cross-site scripting attacks and code injection could also be launched from cached sites, the company said.
bttt
The offending search engines obviously prefer cache to a check.
It’s easy to cache a code with all the viruses out there...
bump
Google cache -bad idea for Mac users?
Since the original zombie bot exploits couldn't affect Macs, why would their ghosts be any more threatening? So no. However, if a Mac user is utilizing Parallels or Fusion to run Windows, then his Windows partition may be at risk.
Thanks.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.