Saturday September 6, 2008 11:11 AM AEST
Latest Comments
"I urge every business person and IT person, management or staff, to get hold of a copy of "I.T. ..."
by John Franks | Sep 6, 2008 1:20 AM
 
"iam intrested in porn movies workes in actors from 36/m india pleas help me thanks."
by vinod agarwal | Sep 5, 2008 8:26 PM
 
"test for intresting"
by cocoboy | Sep 5, 2008 5:39 PM
 
"It's great that Google have recognised that security needs to be an important consideration with ..."
by Lloyd Borrett | Sep 5, 2008 11:53 AM
 
""Google arrived on the browser scene with the launch of Chrome"... Seems a bit misplaced to ..."
by Jeme | Sep 5, 2008 12:33 AM

Spammers send Google links to malware

  • Email a Friend
  • Print Page
Spammers send Google links to malware
By Sue Marquette
Mar 19, 2008 10:17 AM
Tags: "google | links" | "spam | and | google" | "google | security" | "spam | security"
Spammers are using HTML-formatted email that include a link that appears to point to a Google page, but instead directs users to a site that then tries to install malware on their computer.

The link looks like a link to a Google page ad, which conceals the site's actual URL.

“The alarming thing here is that when a user looks at the URL, it will begin with www.google.com, and people trust it,” Craig Schmugar, threat researcher for McAfee Avert Labs, told SCMagazineUS.com on Tuesday.

Spammers have similarly abused this loophole with sites such as MSN and Yahoo.

This exploit has been happening with Google links for several months – it started with trying to get individuals to click on the spammers' websites – but researchers believe that sending users to malicious sites is a new tactic.

Schmugar said this type of phishing scheme can be difficult for some anti-spam solutions to detect.

“If the spam filter is primitive, it may not be able to pick up a valid Google.com redirect from a malicious one,” he said. “There will have to be a decision then whether to block all Google.com redirects, including the valid ones, which would result in a lot of false positives and the users of the site complaining.”

One way users can protect themselves is to run the mouse over the link.

“Look at the full length of the link before clicking,” Schmugar said. “It may be long, but it will show you exactly where it is sending you.”

A Google spokesperson did not immediately return a request for comment.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Messaging Whitepapers