Skip the navigation

Latest Mydoom shows hackers using search engines for attacks

They're using them to find targets and spread worms

By Jaikumar Vijayan
February 22, 2005 12:00 PM ET

Computerworld - Last week's Mydoom worm variant is the latest example of how some hackers are using search engines to spread worms, find easily exploitable targets and unearth vulnerability information for launching attacks (see story).
The Mydoom.be @MM worm first discovered on Feb. 20 was a mass-mailing worm that used its own SMTP engine to send e-mails to addresses it gathered from compromised computers. The worm was also programmed to harvest e-mail addresses from search engines such as Google, AltaVista and Lycos and then use them to distribute itself further.
The worm was similar to last July's Mydoom-O variant, which flooded major search engines and briefly disrupted Google's availability with a similar automated e-mail address searching feature.
Last December's Sanity worm also used Google to search for and attack vulnerable systems by looking for certain specific text on Web sites powered by on open-source bulletin board package. Unlike Mydoom variants, which used the search engines only to harvest e-mail addresses, Sanity used search engines to actually find systems that could be attacked.
The appearance of such worms is an indication that Google hacking -- a term used to describe attacks involving the use of search engines -- is a potent threat, said George Kurtz, senior vice president of risk management at McAfee Inc.
"It's very likely we will see other worms do the same thing," said Graham Cluley, a senior technology consultant at security vendor Sophos PLC. "Search engines such as Google provide an extremely effective way" to gather information that can be used in attacks.
Companies might be surprised at the amount of information available using such search engines, Kurtz said. "It's all about coming up with the right search criteria. By crafting certain requests, you can pull back a lot of very specific information" that can reveal the existence of security flaws such as misconfigured servers, password files and vulnerable software.
The advanced search functions supported by today's popular Web search engines make it relatively easy for even novice hackers to scope out Web sites and gather vulnerability data from around the Internet, Kurtz said.
Google, like other search sites, allows allow users to restrict searches to specific Web sites and domains, to specific files within Web sites, and even to specific pieces of text within those files. Search engines also allow hackers to find out what Web server software version a company might be using, what its directory structure is and when a site was last updated
By using the right search criteria, hackers can turn Google and other



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Malware and Vulnerabilities White Papers
Reducing the Cost and Complexity of Web Vulnerability Management
Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.

Download this...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All Malware and Vulnerabilities White Papers
Malware and Vulnerabilities Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Malware and Vulnerabilities Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs