How can search results lead to malware?

How can search results lead to malware?

I've heard attackers are poisoning search results with malware based on popular queries. What are the best ways to avoid these sites?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Attackers have spent years developing new ways to inject malicious pages into top search results. Search engines aren't fundamentally designed to find trustworthy sites, just popular and relevant ones. As a result, search engine queries often turn up malicious sites. Fortunately, there are a few ways you can reduce your risk.

First and foremost: Use a reputable search engine. Recently, there has been a proliferation of malicious search engines, designed to lure users to dangerous websites. Make sure you are using a well-known, safe search engine, such as Google or Yahoo. Reputable search engines do some filtering to remove malicious sites, although they cannot keep up with the global army of bad guys. If you find a malicious site, you can help by reporting it to Google or your favorite search engine.

There are also various browser plug-ins that will rate sites and display safety indicators next to search results. Check out McAfee Inc.'s SiteAdvisor or Finjan Inc.'s SecureBrowsing tool, for example. At the enterprise level, you can use application-layer proxies, which scan and filter websites. That way, even if users do click on nasty links, you can still block malicious Web content.

Above all: Think before you click.

This was first published in July 2009