Google's Binary Search Helps Dig Up Malware

Mon, July 10, 2006CIO

A little-known capability in Google’s search engine has helped security vendor Websense uncover thousands of malicious websites as well as several legitimate sites that have been hacked, the company said Friday.

By taking advantage Google’s binary search capability, Websense has created new software tools that can sniff out malware using the popular search engine. Websense researchers Googled for strings that were used in known malware like the Bagel and Mytob worms and have uncovered about 2,000 malicious websites over the past month, according to Dan Hubbard, senior director of security and research with Websense.

Though Google is widely used to search the Internet for webpages and office documents, the search engine can also peek through the binary information stored in the normally unreadable executable (.exe) files that are run by Windows computers. "They actually look inside the internals of an executable and index that information," Hubbard said.

Hubbard and his team plan to share their Google code with a select group of security researchers, but they will not make the software public, for fear that the tool could be misused by the bad guys.

Virus authors, for example, could use the Websense software to search for worms and viruses to use in their attacks, Hubbard said. "Instead of buying them on the black market, [an attacker] could search for them and download them on his own."

Some bloggers have pointed out that hackers might also be able to manipulate the binary search feature to trick Google users into downloading malicious software.

Hackers could add common search terms into their malicious code in order to be included in search results, for example, which would then show up alongside legitimate websites.

Google has seen this happen "on occasion," and is making an effort to shield users from this malicious software, a Google spokeswoman said.

This type of attack wouldn’t work unless users clicked on the standard Windows prompt saying that they want the executable code to run on their systems.

And this is something that most Web surfers are smart enough to avoid, according to Johnny Long, a security researcher with Computer Sciences.

"I think the ‘tricking your browser into running an executable file’ trick is a little old," said Long, who wrote the book Google Hacking for Penetration Testers. "There are other more elegant attacks to worry about."

The most interesting thing about Google’s binary search capability is not its security implications, Long said, but the fact that it shows that Google may be thinking about becoming a file-searching service.

Loading...
Network MarketSpace
White Papers
The Challenge of a Demanding Network Infrastructure
Today's data centers are expanding as demand for data and storage continues to grow exponentially. Learn more »
Reduce Infrastructure and Administrative Costs
The Brocade® FastIron® CX Series of switches provides new levels of performance. Learn more »
A New Generation of Application Delivery Controllers (ADCs)
Learn more about Brocade® ServerIron® intelligent application delivery and traffic management solutions. Learn more »
Want to Offer a Superior User Experience?
Control a "boundary-less" enterprise with scalable solutions. Learn more »
Realize Potential Without Increasing Your Risk
Combining Brocade's high-performance infrastructure and McAfee's Web gateway solution ensures trusted environments. Learn more »
Brocade and Imperva: Providing Best-of-Breed Products
Web applications have become the backbone of business in nearly every segment of the economy. Learn more »
 
SPONSORED LINKS
 

Maximizing the Business Value of the PC Infrastructure

Enterprise PBX Comparison Guide

Getting Value from Outdated Networking Equipment

Seven Ways ITIL Can Help You in an Economic Downturn

Data Loss Prevention: A Better Way to Approach Security

Learn how to managing client systems in the enterprise.

Cloud Computing: Read about VMware's compelling vision & set of products

Top-line Performance that's Bottom-line Efficient

Accenture: Outsourcing for uncertain times. Click to learn more.

White Paper: 8 Key Ingredients to Building an Internal Cloud

Read about virtualization and consolidation effort best practices

Building the Virtualized Enterprise with VMware Infrastructure

Top 10 Business and IT Drivers for the Wealth Management Sector

Bottom-Line Benefits of Virtualization

White Paper: The Building Blocks for Cloud Computing

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Learn about The Information Technology Infrastructure Library.

Achieving Pervasive Performance Management

Automating the Generation and Secure Distribution of Excel Reports

Get Google Enterprise Search for your business information.

Accenture IT Consulting: Enabling high performance. More...

Top Five CIO Challenges

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

Taking the Service Desk to the Next Level

Why Data Loss is Increasing--and What You Can Do About It

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Mid-Sized Company CIO Community: infoBOOM!

Accenture IT Consulting: Logical meets technological. More . . .

Stop Application Fraud at the Source with Device Reputation

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

8 Key Ingredients to Building an Internal Cloud

Data Center Optimization: Three Key Strategies

A CIO Executive Guide: Cloud Computing Looms Big on the Horizon

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Tips for successful virtualization management.

Smart Decisions: The Role of Key Performance Indicators

Gartner Shares Predictions for 2009

Introducing the new HP ProLiant G6 server family

Accenture: Outsourcing for Competitive Advantage. More...

Better spam protection with Postini for just $1/user/mo

 
 
RESOURCE CENTER