eWeek Security Watch
Advertisement
Advertisement
August 24, 2010 7:23 PM

Nearly 3 Million Fake YouTube Pages Found Leading to Rogue AV



Researchers at Zscaler have discovered nearly three million fake YouTube pages indexed by Google that lead to rogue anti-virus programs.

Zscaler found the pages by searching under "Hot Video" and a particular URL. Yandex, a Russian search engine, also returns numerous links to the pages as well, the researchers found.

"The fake Youtube video page is covered by an invisible Flash layer and the Flash object automatically redirects the user to a fake AV page," blogged Julien Sobrier, senior security researcher at Zscaler. "If the user has Flash disabled, the page becomes harmless. The URL of the Flash file, hosted on a different domain, is obfuscated with Javascript."

In addition to the huge numbers of pages indexed and the fact they show up in many search results, the pages and their malicious payloads are going virtually undetected, Sobrier wrote.

"This type of threat is different from the usual Blackhat spam SEO: the same content is shown to the user and to the search engine, therefore the page can be accessed directly, without clicking on search engine results," he blogged.

Zscaler has added protection for its customers.

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/20947

Post a Comment

 
 
RSS Syndication
Advertisement

CAG

SEO

Advertisement
Security Watch     Contact Us | Advertise | Site Map
eWEEK Quick LInks

Ziff Davis Enterprise