Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

'Zombie' exploits cached by search engines
TechWorld ^ | 12/07/2007 | By John E. Dunn

Posted on 12/08/2007 12:32:29 PM PST by Swordmaker

Over a year after first coming to light, the cache engines of major search engines are still providing a safe hiding place for malicious code, a security company has revealed.

The latest warning comes from security company Aladdin, which logged an attack against a university Web site which was eventually traced back to just such a 'poisoned cache.' The originating site had been taken offline, but the code from it was still able to spread by living on in the caches of a major search engine.

To make matters worse, cached malicious code could circumvent URL filtering systems because they would only stop the original site URL and not the site as found via a search engine indexing it from cache.

Aladdin didn't specify the engine involved in the incident, but did say the problem affected Google, MSN Live and Yahoo. According to Aladdin's Ofer Elzam, cached pages could remain active for weeks and possibly even months, and would remain in their original state until the cache algorithm refreshed its store.

"As I see it, they [search engines] have done nothing to solve it," he said of the problem. "It is they who are infecting the users. Do they feel responsible?"

This type of cache poisoning was first noticed around four years ago, with Israeli security company Finjan claiming last year that it was also to some extent affecting ISP and enterprise caching systems.

"This is more than just a theoretical danger. It is possible that storage and caching servers could unintentionally become the largest 'legitimate' storage venue for malicious code," said Finjan's CTO Yuval Ben-Itzhak said at the time. "Almost every malicious Web site out there has a copy on a caching server."

The attack documented by Aladdin involved a nest of inter-linked Web sites, and a swarm of over a hundred Trojans, of which 51 were not detectable by signature-based scanning products. Advanced cross-site scripting attacks and code injection could also be launched from cached sites, the company said.


TOPICS: Computers/Internet
KEYWORDS: malware; operatingsystems; spyware; zombies

1 posted on 12/08/2007 12:32:31 PM PST by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: Swordmaker

bttt


2 posted on 12/08/2007 12:51:08 PM PST by Matchett-PI (Algore - there's not a more priggish, sanctimonious moral scold of a church lady anywhere.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; PenguinWry; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; ..

3 posted on 12/08/2007 1:46:43 PM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker; mikrofon; Charles Henrickson
The originating site had been taken offline, but the code from it was still able to spread by living on in the caches of a major search engine.

The offending search engines obviously prefer cache to a check.

4 posted on 12/08/2007 5:04:56 PM PST by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 1 | View Replies]

To: martin_fierro; Charles Henrickson

It’s easy to cache a code with all the viruses out there...


5 posted on 12/08/2007 7:02:03 PM PST by mikrofon (-{snif} -)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker

bump


6 posted on 12/08/2007 7:06:39 PM PST by VOA
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Google cache -bad idea for Mac users?


7 posted on 12/08/2007 7:59:59 PM PST by secretagent
[ Post Reply | Private Reply | To 1 | View Replies]

To: secretagent
Google cache - bad idea for Mac users?

Since the original zombie bot exploits couldn't affect Macs, why would their ghosts be any more threatening? So no. However, if a Mac user is utilizing Parallels or Fusion to run Windows, then his Windows partition may be at risk.

8 posted on 12/08/2007 8:05:48 PM PST by Swordmaker (Entered and posted entirely with my iPhone.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Swordmaker

Thanks.


9 posted on 12/08/2007 10:09:30 PM PST by secretagent
[ Post Reply | Private Reply | To 8 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson