<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Barracuda Labs Internet Security Blog &#187; SEO Poisoning</title>
	<atom:link href="http://www.barracudalabs.com/wordpress/index.php/category/seo-poisoning/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.barracudalabs.com/wordpress</link>
	<description></description>
	<lastBuildDate>Fri, 27 Aug 2010 23:16:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Scammers Cashing in on Facebook &#8216;Un named&#8217; App Hoax</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/01/30/scammers-cashing-in-on-facebook-un-named-app-hoax/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/01/30/scammers-cashing-in-on-facebook-un-named-app-hoax/#comments</comments>
		<pubDate>Sat, 30 Jan 2010 11:55:10 +0000</pubDate>
		<dc:creator>vives</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[SEO Poisoning]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://cs.barracudalabs.net/wordpress/?p=134</guid>
		<description><![CDATA[Posted by: Barracuda Labs
On Wednesday, a seemingly harmless application listing glitch sent numerous users into believing there was a Spybot attack ongoing on Facebook. Due to the bug, an application listed as ‘Unnamed App’ appeared in some users’ application settings. Some of the users took this as the presence of a spybot which would steal [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #888888;">Posted by: Barracuda Labs</span></p>
<p>On Wednesday, a seemingly harmless application listing glitch sent numerous users into believing there was a Spybot attack ongoing on Facebook. Due to the bug, an application listed as ‘Unnamed App’ appeared in some users’ application settings. Some of the users took this as the presence of a spybot which would steal their account details / passwords and perform malicious activities on their computer. Those users warned other users about it and hence the word about ‘Un named App’ spread like a fire in few hours.</p>
<p>Ultimately, this was a harmless bug; however, curious users turned to Google to learn more about it, and scammers saw this as a golden opportunity. The scammers soon harnessed the search query ‘unnamed app’ and poisoned search results to include sites that would redirect users to a Rogue AntiVirus serving site instead. This has become a very popular technique used by scammers in the past few months.</p>
<p><a href="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/01/searchresult_1.png"><img class="alignnone size-full wp-image-138" title="searchresult_1" src="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/01/searchresult_1.png" border="0" alt="" width="600" /></a></p>
<p>Clicking on search results titled ‘Unnamed App’ redirects user to Rogue AV:</p>
<p><a href="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/01/RogueAvPopup_1.png"><img class="alignnone size-large wp-image-139" title="RogueAvPopup_1" src="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/01/RogueAvPopup_1-1024x645.png" border="0" alt="" width="600" /></a></p>
<p>Scam artists also attempted to hide from the research community by selectively redirecting only users who visited straight from Google by clicking one of the search results. Visitors (mostly researchers) who attempted to go to the malicious search result directly were redirected to <a href="http://www.cnn.com/" target="_blank">http://www.cnn.com</a> instead.</p>
<p>There are multiple ways to achieve this. In this case, attackers reviewed the referrer-header to check from where the user came.</p>
<p>Hence what was seemingly a harmless bug, was still able to perform some damage to the innocent users’ browsing experience today.</p>
<p>Users of the <a href="http://www.purewire.com/purewire_web_security_service.php" target="_blank">Barracuda Purewire Web Security Service</a> are protected from this attack.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F01%2F30%2Fscammers-cashing-in-on-facebook-un-named-app-hoax%2F&amp;linkname=Scammers%20Cashing%20in%20on%20Facebook%20%26%238216%3BUn%20named%26%238217%3B%20App%20Hoax"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/01/30/scammers-cashing-in-on-facebook-un-named-app-hoax/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yet Another Reputable Site Asks You to Install Rogue AV</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2009/12/18/yet-another-reputable-site-asks-you-to-install-rogue-av-2/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2009/12/18/yet-another-reputable-site-asks-you-to-install-rogue-av-2/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 11:29:42 +0000</pubDate>
		<dc:creator>vives</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[SEO Poisoning]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://10.8.0.141/wordpress/?p=114</guid>
		<description><![CDATA[Posted by: Barracuda Labs
Yet another reputable site has fallen victim to compromise — University of Arkansas.
This Tuesday, Barracuda’s Malicious Javascript Detection engine (MJD) identified Rogue AV software being distributed from a page that belongs to the University of Arkansas Web site. When users accessed a particular page from the university Web site, it opened a [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #888888;">Posted by: Barracuda Labs</span></p>
<p>Yet another reputable site has fallen victim to compromise — University of Arkansas.</p>
<p>This Tuesday, Barracuda’s Malicious Javascript Detection engine (MJD) identified Rogue AV software being distributed from a page that belongs to the University of Arkansas Web site. When users accessed a particular page from the university Web site, it opened a window warning them about their computer being infected with viruses and then subsequently downloaded an anti-virus software which was identified to be a fake anti-virus software.</p>
<p>A forensic analysis of the attack revealed that the user requested the following:</p>
<p><span style="color: #ff0000;">hxxp://bumperscollege.uark.edu/ssp_director/inc/html/d/georgia-inmate-query.html</span></p>
<p>which in turn requested a javascript from a malicious domain via script include:</p>
<p><span style="color: #ff0000;">hxxp://xrusx.com/counter.php?sref=bumperscollege.uark.edu/ssp_director/inc/html/d/georgia-inmate-query.html</span></p>
<p>which contained further malicious javascript includes that generated fake warning messages on the user’s computer.</p>
<p><a href="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/12/uark_malwareWarning-resized-600.png"><img class="alignnone size-full wp-image-119" title="uark_malwareWarning-resized-600" src="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/12/uark_malwareWarning-resized-600.png" alt="" width="600"  border="0" /></a></p>
<p>And ultimately attempted to download setup.exe:</p>
<p><a href="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/12/uArk_rogueAV2_resize-resized-600.png"><img class="alignnone size-full wp-image-120" title="uArk_rogueAV2_resize-resized-600" src="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/12/uArk_rogueAV2_resize-resized-600.png" alt="" width="600"  border="0"/></a></p>
<p>setup.exe was linked off another malicious domain:</p>
<p><span style="color: #ff0000;">hxxp://www.loker.us/forum/attachments/setup.exe</span></p>
<p>While investigating deep into the tracks of the user to determine how the user got to this page, we made yet another interesting discovery. Our investigation could not find user browsing a page linking directly off Universityof Arkansas linking the malicious page that was distributing the Rogue AV. Instead, it was a Bing search result that lead user to this page. Specifically, one customer using the Barracuda Purewire Web Security Service searched for ‘georigainmatequery’ on Microsoft Bing search engine.</p>
<p><span style="color: #ff0000;">hxxp://www.bing.com/search?q=georgiainmatequery</span></p>
<p>Which yielded following results:</p>
<p><a href="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/12/uArkbingpage_georgiainmatequery-resized-600.png"><img class="alignnone size-full wp-image-121" title="uArkbingpage_georgiainmatequery-resized-600" src="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/12/uArkbingpage_georgiainmatequery-resized-600.png" alt="" width="600"  border="0" /></a></p>
<p>As you can see, the malicious link from uArk.edu shows up in the bing search results — and in the number two spot. The page is leveraging uArk.edu’s reputation ranking in what we’ve previously reported on as SEO poisoning (see previous post). This is becoming increasingly more popular as hackers are targeting vulnerabilities in legitimate Web sites since it makes the malicious page more likely to be visited. While search engines have been proactively adding malware scanning in their arsenal, legitimate Web site owners also need to take proactive steps to keep their site free of such malicious content.</p>
<p>Customers using the Barracuda Purewire Web Security Service are protected from this attack.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2009%2F12%2F18%2Fyet-another-reputable-site-asks-you-to-install-rogue-av-2%2F&amp;linkname=Yet%20Another%20Reputable%20Site%20Asks%20You%20to%20Install%20Rogue%20AV"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2009/12/18/yet-another-reputable-site-asks-you-to-install-rogue-av-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
