November 27, 2009 | Misc

The Unmask Parasites blog has uncovered a devious method being used by a particular network of malware sites. Maleware purveyors are creating subdirectories in legitimate blogs where they host their own illegitimate blogs.

The illegitimate blogs are targeted toward very specific and unpopular Google search terms, such as “blue mustang picture”, “upstate ny photos”.

Interestingly, the malware isn’t presented if you go directly to the site, only if you go through Google. The malware is presented in the form of bogus anti-virus software, but not directly. Rather, obfuscated Javascript redirects are used to prevent blacklisting.

Unmask Parasites cites this as another reason to be running the Firefox NoScript plugin, which allows Javascript only for specified sites.

Another plugin for this purpose, much simpler than NoScript, is QuickJava, which allows you to turn Javascript on and off with a single click.

It’s also another reason to keep WordPress (or whatever blog software you’re using) updated and to regularly check your installation for problems.

Read the details of the malware network at Unmask Parasites.


If you liked this article

If you liked this article, don’t forget to subscribe for updates!

Subscribe to New Articles by RSS or E-mail

Get updates by RSS (What’s RSS?)

Subscribe by email:

Follow me on Twitter

Top Incoming Search Terms

Related posts:

  1. Google Chrome Browser Third Place Behind Internet Explorer and Firefox A new survey is showing that Google’s Chrome browser is...
  2. English Shellcode: A New Method for Malware Attacks The wedge end of malware code can be made to...
  3. Facebook Surpasses Google: What Does It Mean? A number of sources are reporting Facebook has surpassed Google...
  4. Firefox and Chrome Complicate Mozilla and Google Ties In a Computerworld article, Mozilla CEO John Lilly calls the...
  5. Microsoft’s Bing Search Engine Has Google Scared? The New York Post is reporting that Google is afraid...

Explore related content: , ,

Leave a Reply

CommentLuv Enabled