The Santy.a worm found its victims through an automated Google search query
The latest 'Google hack' uses the search tool for automated vulnerability detection

Worms turn on Google to hunt for victims

Google 'hacking' so simple even a monkey could do it

Written by Tom Sanders at RSA Conference in San Jose

Malware authors are increasingly creating digital pests that use Google to find their next victim.

Using the search tool for automated vulnerability detection is the latest trend in a technique known as 'Google hacking'.

George Kurtz, senior vice president for risk management at security firm McAfee, told vnunet.com about the phenomenon after a presentation at the RSA Conference in San José.

The Santy.a worm, for instance, targeted a known vulnerability in some versions of the phpBB open source bulletin board application to deface websites. It found its victims through an automated Google search query.

Google eventually stopped the worm from spreading by blocking all searches that would turn up servers running the application. But the search engine is able to detect the abuse only if the queries stand out from other searches.

Google 'hacking' does not mean breaking into the company's servers but involves online criminals using Google and other search engines to find sensitive information on the internet.

Hackers have used search engines to assist in break-ins ever since the creation of online search.

Tags:

Further reading

Microsoft promises security without passwords

Bill Gates touts Infocards as the future of online authentication   More...

Sun talks up next-gen cryptography

Elliptic Curve Cryptography touted for mobile devices   More...

Related articles

Cyber-attack launched from 10,000 web pages

Unsuspecting surfers redirected to site laden with malware   More...

SMEs vulnerable to growing web threats

Small companies need to wise up to spyware   More...

Infosec: Rock Phish threat deepens

Hugely successful malware gets a new twist   More...

Windows 2000 flaw highlights slow Patch Tuesday

Vista and XP spared from most dangerous vulnerabilities   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

18 Jul 2008

7.91 MBPodcast Special: Views from the Valley More...

17 Jul 2008

3.61 MBMalware explosion, nanotech fears and a jailed spammer More...

16 Jul 2008

4.17 MBiPhone 3G hacked, YouTube privacy deal and BT ad complaints More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement