This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Windows Live Search - "malware-related returns"

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.theregister.com/2007/03/20/windows_live_malware/
20 March 2007 ~ "…According to researchers at Sunbelt-Software, Live.com's affair with malicious sites runs so torrid that malware-related returns on the search engine number in the thousands. Terms that trigger similar results tend to be Italian phrases, including, to name a few, "adsl offerta toscana," "istituto geografico italiano," "dvd da scaricare" and "testi reggae." Sunbelt blogged here* about the sludge fest two weeks ago, but Live.com has continued to spew the noxious results unabated. Google and Yahoo long ago managed to filter most of the same sites from their returns. "I don't think it was very responsible to keep these malware sites up for so long," says Francesco Benedini, a spyware researcher at Sunbelt. "I'm not saying Google and Yahoo! don't have a problem, but it's much more invasive on Live.com." A Microsoft representative says in a statement that "to the extent that spammers are successful in essentially manipulating results, they will hurt the user experience on all search engines". That left us scratching our heads for a couple reasons. For one, the same search terms don't appear to generate malicious returns on Google or Yahoo!…"

* http://sunbeltblog.blogspot.com/2007/03/ma…e-searches.html
March 06, 2007 ~ "It looks like the malware people have practically taken over Live search in Italy. 95% or more of the following search results lead to extremely nasty malware and exploit sites (namely rustock.b or Gromozon)…"

:ph34r:
FYI…

Search Engine Poisoning(!)
- http://www.websense.com/securitylabs/blog/….php?BlogID=116
Mar 26 2007 ~ "Search Engine Poisoning is a topic that we have have researched at some length. We discussed the topic briefly in an October blog post: Search Engine Typosquatting*. Our previous research focused on malicious URLs in search engine results from misspelled search terms; it was far less common to discover malicious content for legitimate search terms. In early March, a report from Sunbelt** demonstrated Microsoft Windows Live Search™ Italy returning exploit sites for extremely common search terms. Doing some additional research of our own, we performed searches for the names of financial companies, well-known banks, and lenders. The results were alarming. Many of the URLs in the search results linked to malicious sites capable of silently compromising the visitor…"

(More detail and screenshots at the URL above.)


* http://www.websense.com/securitylabs/blog/blog.php?BlogID=88

** http://sunbeltblog.blogspot.com/2007/03/ma…e-searches.html

:ph34r: