The InformationWeek -- Blogs
Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

You Aren't Safe. Get Over It


Posted by Alice LaPlante, Apr 26, 2007 02:32 PM

The latest news to add to the list of online perils to be paranoid about comes courtesy of the Washington Post. Virus writers apparently have a new scheme for distributing malicious code: purchasing popular Google keywords and publishing ads that purport to lead users to legitimate Websites. Some of the keywords the tricksters bought include "BBB" (for Better Business Bureau) and "Cars.com."


The catch is that clicking on these ads really directs users to nasty places where a particularly damaging piece of malware lurks. If you didn't install an IE patch issued by Microsoft in June 2006, and if you're unlucky enough to be lured to one of these dubious sites, a flaw in Microsoft Windows downloads software that steals passwords and sensitive financial information from your PC. This exploit was identified by Exploit Prevention Labs; it echoes a similar one caught by Security Fix in mid 2006 in which a banner ad on MySpace linked users to an equally dangerous URL.

Yes, as respondents to the article have pointed out, you could put the blame on compromised users because they failed to install the IE patch. But let's face it: If you're reading this post on the InformationWeek Website, you almost certainly possess a certain amount of technical acumen--probably more than 99 percent of the general Internet-using population. Unfortunately, a significant proportion of the rest of the world isn't aware of the supreme importance of installing security patches, and moreover depends on the reputation of big-name brands like Google to shield them against tricks like this. Yes, it's naïve. But it explains the alarming statistics of why so many PCs of less-technically-expert people get infected so fast and so frequently.

This latest nefarious antic certainly gave me pause: I use Google sponsored links all the time. And--clearly wrongly--the fact that they appear on the Google search results page has always increased my sense of their legitimacy. One more thing to put on my personal list.

What about you? What of all the continuous stream of malicious tricks particularly alarm you? Have you ever fallen for one? Has anyone near and dear to you been tricked into giving up sensitive data? Let us hear your stories.

« We The ('Net) People: Who Owns The Presidential Debates? | Main | Do Wireless Subscribers Really Want Mobile Net Neutrality? »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Sequential Programming: Like Eating Peas with a Straw.
  2. Biomolecular device using self-assembled DNA nanostructures?
  3. Coreinfo v2.0: A Simple Utility to Understand the Manycore Complexity in Windows


Join The InformationWeek Group On LinkedIn


                           


  1. More Reasons Why Linux Misses The Desktop
  2. Too Much Netbook For Too Litl?
  3. Verizon: $350 ETF Is A Go
  4. Motorola Explains Why Droid Doesn't Have Multi-Touch


  1. Florida Hospital Dials Up iPhones For Nurses
  2. Full Nelson: A Web Presence Needs Sizzle, My Nizzle
  3. Is Antivirus Software Dead?
  4. Practical Analysis: The Fastest-Growing Security Threat
  5. InformationWeek Analytics Research: Federated Search
  6. Securing The Cyber Supply Chain

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007