labels: it news
Websense uses Google capability to dig up malware news
07 July 2006
Thanks to a little-known capability in Google Inc.'s search engine, security vendor Websense has uncovered thousands of malicious Web sites as well as several legitimate sites that have been hacked, the company said Friday.

Taking advantage Google's binary search capability, Websense has created new software tools that can sniff out malware. According to Websense researchers, they Googled for strings that were used in known malware like the Bagel and Mytob worms and have so far uncovered about 2,000 malicious Web sites over the past month.

Websense officials said that Google can also peek through the binary information stored in the normally unreadable executable (.exe) files that are run by Windows computers and index that information. The company now says that it plans to share its Google code with a select group of security researchers. It will not make the software public, lest it be misused by malware creators. The danger lies in that virus authors could then use the Websense software to search for worms and viruses to use in their attacks, instead of buying them on the black market.

Another danger, according to software researchers is that hackers might also be able to manipulate the binary search feature to trick Google users into downloading malicious software. Hackers could add common search terms into their malicious code in order to be included in search results, for example, which would then show up alongside legitimate Web sites.

Meanwhile Google a spokesperson has confirmed that the search engine has seen this happen "on occasion," and is making an effort to shield users from this malicious software. It is pointed out that this type of attack wouldn't work unless users clicked on the standard Windows prompt saying that they want the executable code to run on their systems. Fortunately most Web surfers are smart enough to avoid the trap, according to security researchers. They however warn that there are other more elegant attacks for users to worry about.


 search domain-b
  go
 
Websense uses Google capability to dig up malware