Advertisement
Promo

Security threats Toolkit

Google removes malicious advertising links

Joris Evers CNET News

Published: 30 Apr 2007 09:21 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Google has removed paid links that advertised seemingly legitimate websites but actually tried to install nefarious programs on PCs.

The links were displayed as "sponsored links" after visitors entered specific queries into Google's search service. Clicking the links would ultimately go to a legitimate site, but by way of another site that attempted a "drive-by installation" of password-stealing software. Miscreants placed the links using Google's AdWords service for advertisers.

"Google identified and cancelled AdWords accounts displaying ads that re-directed users to malicious sites", a company representative wrote on a corporate blog on Thursday.

The malicious links appeared after people searched for terms related to the Better Business Bureau and cars, according to Exploit Prevention Labs, a security company. All the paid-for links masqueraded as legitimate sites and redirected Google users to the actual sites after sending them to smarttrack.org, which served up the malicious code, Exploit Prevention Labs said.

"We detected about 20 different search strings that resulted in links to smarttrack.org," said Roger Thompson of Exploit Prevention Labs. "There were multiple ads linking to a single site, a high level of planning, and cunning by the bad guys."

Web threats are on the rise. Security firm Trend Micro predicts that by next year, internet users can expect more cyberattacks to originate from the web than via email. The threat hasn't gone unnoticed by the security industry. Tools such as Google's Toolbar for Firefox or Google Desktop, Exploit Prevention Labs' LinkScanner and McAfee's SiteAdvisor can offer protection by blocking known bad sites or rating search results.

Google is looking at its AdWords practices to prevent similar incidents in the future, the company said. "This is an issue we've taken very seriously and will continue to monitor," it said. "We are also evaluating our systems to ensure that the appropriate measures are in place to block future attempts."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
28 out of 28 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Microsoft MUI and a LIP

I was asked by a client today what the difference between a Microsoft MUI and a LIP. And, more importantly, "what were the application compatibility consequences of multi-language support?" I... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters