Orice anunt din Romania adaugat aici va fi sters!
Researchers from the firm surveyed billions of sites, subjecting 4.5 million pages to "in-depth analysis".
About 450,000 were capable of launching so-called "drive-by downloads", sites that install malicious code, such as spyware, without a user's knowledge.
A further 700,000 pages were thought to contain code that could compromise a user's computer, the team report.
To address the problem, the researchers say the company has "started an effort to identify all web pages on the internet that could be malicious".
Phantom sites
Drive-by downloads are an increasingly common way to infect a computer or steal sensitive information.
They usually consist of malicious programs that automatically install when a potential victim visits a booby-trapped website.
"To entice users to install malware, adversaries employ social engineering," wrote Google researcher Niels Provos and his colleagues in a paper titled The Ghost In The Browser.
Finding all the web-based infection vectors is a significant challenge and requires almost complete knowledge of the web
Google researchers
|
"The user is presented with links that promise access to
'interesting' pages with explicit BLOCKEDographic content, copyrighted
software or media. A common example are sites that display thumbnails
to adult videos."
The vast majority exploit vulnerabilities in Microsoft's Internet Explorer browser to install themselves.
Some downloads, such as those that alter bookmarks, install unwanted toolbars or change the start page of a browser, are an annoyance. But increasingly, criminals are using drive-bys to install keyloggers that steal login and password information.
Other pieces of malicious code hijack a computer turning it into a "bot", a remotely controlled PC.
Drive-by downloads represent a shift away from traditional methods of infecting a computer, such as spam and email attachments.
Attack plan
As well as characterising the scale of the problem on the net, the Google study analysed the main methods by which criminals inject malicious code on to innocent web pages.
Spam e-mails are a common way to infect a computer
|
It found that the code was often contained in those parts of the website not designed or controlled by the website owner, such as banner adverts and widgets.
Widgets are small programs that may, for example, display a calendar on a webpage or a web traffic counter. These are often downloaded form third party sites.
The rise of web 2.0 and user-generated content gave criminals other channels, or vectors, of attack, it found.
For example, postings in blogs and forums that contain links to images or other content could unwittingly infect a user.
The study also found that gangs were able to hijack web servers, effectively taking over and infecting all of the web pages hosted on the computer.
In a test, the researchers' computer was infected with 50 different pieces of malware by visiting a web page hosted on a hijacked server.
The firm is now in the process of mapping the malware threat.
Google, part of the StopBadware coalition, already warns users if they are about to visit a potentially harmful website, displaying a message that reads "this site may harm your computer" next to the search results.
"Marking pages with a label allows users to avoid exposure to such sites and results in fewer users being infected," the researchers wrote.
However, the task will not be easy, they say.
"Finding all the web-based infection vectors is a significant challenge and requires almost complete knowledge of the web as a whole," they wrote.
Sursa: BBC News
Nasterea noului PSD !!! Cine este, insa, mama lui ??? |
Mesaj catre Parlament: Nu mai vreau sa astept 1 ianuarie 2007 ! Eu vreau sa intru in UE ...ACUM!!! |
Tablou modern intitulat "Dansand cu lupii", infatisandu-l pe Nastase, care a fost lucrat pe (din) toate partile fiind factorul care a coagulat, in final, opozitia si puterea. |
Eugen Nicolaescu, un ministru caruia Sorin Oprescu i-a demonstrat, via Curtea Constitutionala, ca la Elias pacientii noi sunt tot aia vechi |
Lupta in interiorul si exteriorul PSD-ului. Adrian Nasase fata in fata cu reactiunea |
Revolta in PSD. Grupul de la Cluj si de unde o mai fi el se "da" la Nastase. Tare de tot! ....."Orice sut in fund inseamna un pas inainte shefu! Daca tot nu am apucat sa-ti numar ouale macar sa ti le fac omleta." |
Colegii din PSD care inteleg sintagma "mai cu perdea", prin "mai cu manusi". "Frate! Soro! Nu mai dati asa la mine! Sistemul asta ticalosit m-a spart de tot. Nu! Si nu! Si nu! Camera deputatilor este a mea! Nici a voastra, nici a lui Base." |
Intalnire de gradul trei: Traian Basescu, blondele si "Mama Natura" |
Traian Basescu, acest "Tata Natura" al politicii romanesti, intr-o incercare de a-i arata blondei o noua pozitie. Ea n-a inteles. |
Auzi draga?! Atunci cand am hotarat sa dau suvita jos nu inseamna ca toti trebuie sa va dati suvitele jos! Mai bine stinge lumina si hai sa-ti arat ce ceas cu fosfor am! |
"Ai em za ching af za uorld!", zicea unu, vaporean ca si mine. Ha-ha-ha-ha! N-a auzit el de Golden Blitz, restaurant cu specific romanesc. Papusa, ce-ai zice de un briefing acolo, ca tot esti imbracata in costum popular?! |
Iarna nu-i ca vara! |
Ma numesc DIANA TOFAN si sunt personal trainer calificat.Doritorilor de sport si exercitii fizice pentru intretinere,slabire si modelare a corpului ofer asistenta si sfaturi in domeniu.Ma puteti contacta la numarul de telefon cell:239-465-6062 sau la sediul XSport gym situat pe 3240 N ASHLAND,.CHICAGO,IL .Deasemenea cei interesati pentru un membership pot sa ofer discount si o ora gratis pentru consultanta.E-mail adress This email address is being protected from spambots. You need JavaScript enabled to view it. |
03/28/07 | |
Ma numesc DIANA TOFAN si sunt personal trainer calificat.Doritorilor de sport si exercitii fizice pentru intretinere,slabire si modelare a corpului ofer asistenta si sfaturi in domeniu.Ma puteti contacta la numarul de telefon cell:239-465-6062 sau la sediul XSport gym situat pe 3240 N ASHLAND,.CHICAGO,IL .Deasemenea cei interesati pentru un membership pot sa ofer discount si o ora gratis pentru consultanta.E-mail adress This email address is being protected from spambots. You need JavaScript enabled to view it. |