Skip Links

Network World

  • Social Web 
  • Email 
  • Close

'Zombie' exploits cached by search engines

By John E. Dunn , TechWorld , 12/07/2007

Over a year after first coming to light, the cache engines of major search engines are still providing a safe hiding place for malicious code, a security company has revealed.

The latest warning comes from security company Aladdin, which logged an attack against a university Web site which was eventually traced back to just such a 'poisoned cache.' The originating site had been taken offline, but the code from it was still able to spread by living on in the caches of a major search engine.

To make matters worse, cached malicious code could circumvent URL filtering systems because they would only stop the original site URL and not the site as found via a search engine indexing it from cache.

Aladdin didn't specify the engine involved in the incident, but did say the problem affected Google, MSN Live and Yahoo. According to Aladdin's Ofer Elzam, cached pages could remain active for weeks and possibly even months, and would remain in their original state until the cache algorithm refreshed its store.

"As I see it, they [search engines] have done nothing to solve it," he said of the problem. "It is they who are infecting the users. Do they feel responsible?"

This type of cache poisoning was first noticed around four years ago, with Israeli security company Finjan claiming last year that it was also to some extent affecting ISP and enterprise caching systems.

"This is more than just a theoretical danger. It is possible that storage and caching servers could unintentionally become the largest 'legitimate' storage venue for malicious code," said Finjan's CTO Yuval Ben-Itzhak said at the time. "Almost every malicious Web site out there has a copy on a caching server."

The attack documented by Aladdin involved a nest of inter-linked Web sites, and a swarm of over a hundred Trojans, of which 51 were not detectable by signature-based scanning products. Advanced cross-site scripting attacks and code injection could also be launched from cached sites, the company said.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (1)
Login
Forgot your account info?

RE: 'Zombie' exploits cached by search enginesBy Anonymous on December 7, 2007, 12:53 pmHeck no, they aren't responsible. If your dumb butt pulls up a cached version of a poisoned site, you're responsible.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Magic Quadrant for Application Delivery Controllers

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...

Vulnerability Management For Dummies

Download this concise book "Vulnerability Management for Dummies," to learn about the simple steps...

The ROI and TCO Benefits of Data Deduplication for Data Protection in the Enterprise

This paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Webcasts

Transforming the Enterprise WAN Edge: Video from Cisco

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.