« Koobface or Rogueware? Your choice.
HoneyPot Workflow »

Do search engines really protect you from malware?

July 28th, 2009

We make tens, hundreds or maybe thousands  of queries on search engines every day. We want them to be fast and accurate and trust the results it displays back to us.

I believe search engines should be held accountable (in some cases) for the content they link to. The particular instances I am thinking of, are those links that push malware.

I tried a little experiment. I searched for a known malware domain: google-hostcom.ru

This site contains adult content and tries to download a malicious file onto the user’s computer:

fake

Here are the results from the most popular search engines:

Google:

goo

Yahoo!

yah

bing

bing

Ask.com

ask

Conclusion:

Practically all search engines list this malicious domain without any warning of any sort.

AV vendors, such as Paretologic, maintain up-to-date blacklists. I believe Sunbelt Software just started on working with Stopbadware.org, the organism that provides information about the Google warnings.
However, there is clearly a lot of room for improvement as this experiment just proved.

We need to combine our intelligence together in order to make the web safer!

Jerome Segura

    This entry was posted on Tuesday, July 28th, 2009 at 4:49 pm and is filed under Exploits. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    2.      by
    3.      by
    • (3) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (109)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.