Malicious code is living on weeks after it has been removed from websites thanks to an unexpected culprit: cache servers.
According to Finjan Software, which has just released its latest Web trends report, caching technology used by search engines, ISPs and large companies has been discovered to harbor certain kinds of malicious code even after the website that hosted it has been taken down.
The company offered details of how code designed to exploit a number of vulnerabilities in Microsoft products from 2003 and 2004 was able to continue in the public domain, thanks to it hiding in the cache servers of one of three unnamed search engines.
Although it is old, there is no reason why the same issue wouldn’t apply to recent issues on an unlimited scale, depending on the nature of the code and the way it was buried within cacheable content. And code pointing to malware such as Trojans would remain because of the issue, raising the level of risk further.
“This is more than just a theoretical danger. It is possible that storage and caching servers could unintentionally become the largest ‘legitimate’ storage venue for malicious code,” said Finjan CTO Yuval Ben-Itzhak. “Almost every malicious website out there has a copy on a caching server.”
The services affected by the cached malware had been informed in August. “What our latest report shows is that current processes to remove such malicious content from the Web are simply not going far enough to combat this very serious and growing threat.”
This type of threat counts as new, though there have been several instances of malicious code using search engines to spread in other ways. In May, a McAfee report claimed that search engines were now a major channel for the inadvertent spread of malware by returning infected sites in search results.
-John E. Dunn, Techworld.com (London)
Check out our CIO News Alerts and Tech Informer pages for more updated news coverage.