Ads by TechWords

See your link here
Receive the latest technology news and information.
Networking
Networking Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

'Zombie' exploits cached by search engines

December 7, 2007 12:00 PM ET

TechWorld.com - More than a year after first coming to light, the caches of major search engines are still providing a safe hiding place for malicious code, a security company has revealed.

The latest warning comes from security company Aladdin Knowledge Systems Ltd., which logged an attack against a university Web site that was eventually traced back to just such a "poisoned cache." The originating site had been taken offline, but the code from it was still able to spread by living on in the caches of a major search engine.

To make matters worse, cached malicious code could circumvent URL filtering systems because they would stop only the original site address and not the site as found via a search engine indexing it from cache.

Aladdin didn't specify the engine involved in the incident, but did say the problem affected Google Inc., MSN Live and Yahoo Inc.. According to Ofer Elzam, director of product management for Aladdin eSafe, cached pages could remain active for weeks and possibly even months, and they would remain in their original state until the cache algorithm refreshed its store.

"As I see it, they [search engines] have done nothing to solve it," he said of the problem. "It is they who are infecting the users. Do they feel responsible?"

This type of cache poisoning was first noticed around four years ago, and security company Finjan Inc. claimed last year that it was also to some extent affecting Internet service providers and enterprise caching systems.

"This is more than just a theoretical danger. It is possible that storage and caching servers could unintentionally become the largest 'legitimate' storage venue for malicious code," Finjan Chief Technology Officer Yuval Ben-Itzhak said at the time. "Almost every malicious Web site out there has a copy on a caching server."

The attack documented by Aladdin involved a nest of interlinked Web sites, and a swarm of over 100 Trojan horses, of which 51 were not detectable by signature-based scanning products. Advanced cross-site scripting attacks and code injection could also be launched from cached sites, the company said.


Reprinted with permission from

For more enterprise technology news from the U.K., please visit TechWorld.com. Copyright 2006 IDG, all rights reserved.

Jump to comments

zombie

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

What People Are Saying

White Papers & Webcasts

Tackling the Top Five Network Access Control Challenges
Computerworld and Juniper invite you to download this white paper.  

How to Secure and Accelerate Your Oracle Applications
Learn about the escalating application performance and security challenges facing corporations, today!  

Enterprise Application Delivery: No User Left Behind
Gain the ability to deliver applications to all users, using any device, across any network.  

Accelerate SSL Encrypted Applications
Gain complete visibility into SSL application sessions, making it easy to apply appropriate acceleration and security controls to all SSL traffic.  

The Commercialization of ITIL: Lessons Learned
Register for this event today!