Skip to main content

One in Ten Web Pages Malicious, Says Google

In a paper entitled “The Ghost in the Browser” (PDF) presented at the Usenix HotBots ’07 conference in April, Google researchers outlined a study which performed an in-depth analysis of some 4.5 million Web pages—condensed from a high-level analysis of several billion URLs. The researchers found found that about 700,000 pages looked to contain code which could compromise a user’s computer, and about 450,000 (or 1 in 10) could trigger so-called “drive-by downloads” that could install malicious software without the user’s knowledge, including keyloggers, spyware, and software capable of taking over a user’s machine and turning it into a spam generator.

The researchers found that in many cases, Web users are tricked into loading the malware-laden Web page by promises of software or media downloads, or—of course—adult material. The sites would claim the user needed a new codec or other component to use the files; the user would instead unwittingly install malware. Many of these sites have no significant Web presence of their own, leading researchers to speculate that traffic is being driven to them via email spam.

Recommended Videos

Other sites were found to be distributing malware through the use of banner advertisements or so-called “widgets” which weren’t under the direct control of the site operator. Some sites would tie into advertising networks or services which offered on-page utilities like statistics analysis, calendars, or media players; those utilities in turn referenced third-party sites, which would attempt to install malware.

Researchers also found that attackers were attacking entire Web servers (converting almost every page on the compromised server into a malware host), and that attackers were taking advantage of blog comment features and other Web 2.0 means of eliciting user-generated content as means to promote malware sites or to distribute software-based attacks.

The overwhelming majority of attempted exploits targeted vulnerabilities in Microsoft’s Internet Explorer Web browser.

Although Google attempts to warn users of potentially harmful sites listed in its search engine, the researchers’ conclusions are grim. “The sophistication of adversaries has increased over time and exploits are becoming increasingly more complicated and difficult to analyze,” wrote researcher Niels Provos and his colleagues. “Unfortunately, average computer users have no means to protect themselves from this threat.”

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
I finally upgraded my Google One storage. Here’s why I might never do it again
Google Drive in Chrome on a MacBook.

As a technology journalist and food photography enthusiast, I can collect thousands of images at a rapid pace.

And if you’ve also spent a considerable amount of time online, there’s a good chance you’re connected to some sort of paid cloud storage. For me, that system is Google One. I got sucked in back when Google storage was free, but around 2019, the paid Google One subscription service was established. At $20 per year for 100GB of storage, it was a no-brainer for someone like myself, who stores a ton of data online. But a few years on, I'm in the exact same situation I was before. I need more storage space.

Read more
Google Calendar just fixed one of its most irritating bugs
Google Calendar shown on a computer monitor.

If you like to combine Google Calendar with your Microsoft Outlook account, we’ve got some good news: Google has finally fixed an issue that has been plaguing the two services for way too long.

Previously, if you were to organize a meeting in Outlook, you would frequently find that your name was missing from the list of attendees in Google Calendar. This would obviously be confusing for other users, as it would seem that you weren’t planning on showing up to a meeting you were known to be organizing.

Read more
Google is creating ‘internet surveillance DRM,’ critics say
Google Drive in Chrome on a MacBook.

Google is working on a system to fight fraud and make the internet “more private and safe,” but it’s just come in for some blistering criticism from software engineers behind the Vivaldi web browser. According to them, it’s a “dangerous” idea that could lead to greater surveillance of ordinary people.

The subject of this kerfuffle is Google’s Web Environment Integrity project, or WEI. Its purpose, Google says, is to stymy bad actors by providing a piece of code on a website that can be checked with a trusted attestor (such as Google) to ensure the visitor is who they say they are. That could prevent cheating in games, for example, or ensure that ads are being properly served to readers.

Read more