Advertisement
Promo

Security threats Toolkit

Google's Blogger top for web-hosted malware

Robert Vamosi and Alex Serpo ZDNet Australia

Published: 25 Jul 2008 08:44 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Google has catapulted itself to the top of the ranks of web hosts with the most malware, courtesy of its blogging website Blogger, according to security vendor Sophos.

"During June, two percent of all the web-hosted malware we found was on that site," Sophos security researcher Paul Ducklin said.

However, Ducklin defended the search giant, saying that the amount of malware present on Blogger was due to the popularity of the site. "If a particular internet service provider has the most customers, they would probably, de facto, have the most computers on their network which are zombies," he said.

Read this

Comment
Comment: The man who transformed internet security

When security researcher Dan Kaminsky discovered a potentially disastrous flaw within the Domain Name System, his measured response led to the biggest-ever multiparty patch release

Read more +

"With Google there is so much space in there... but it is surprising — two percent is enormous," Ducklin said. Sophos said the most common form of malware was SQL injection attacks, with one new infected web page discovered every five seconds.

Ducklin said sites like Blogger and others were also a prime target. "The cybercriminals are actively targeting sites that not only permit but actively encourage people to upload external content, including links to stuff of interest."

A spokeperson for Google told ZDNet.co.uk sister site CNET News.com: "Google takes the security of our users very seriously and we work hard to protect them from malware. Using Blogger, or any Google product, to serve or host malware is a violation of our product policies. We actively work to detect and remove sites that serve malware from our network."

Credit: Google's Blogger number one for malware from ZDNet Australia

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters