{"id":83254,"date":"2017-07-04T16:36:26","date_gmt":"2017-07-04T05:36:26","guid":{"rendered":"http:\/\/smartoffice.com.au\/drive-by-code-infecting-web-sites-say-google\/"},"modified":"2017-07-04T16:36:26","modified_gmt":"2017-07-04T05:36:26","slug":"drive-by-code-infecting-web-sites-say-google","status":"publish","type":"post","link":"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/","title":{"rendered":"Drive By Code Infecting Web Sites Say Google"},"content":{"rendered":"<p>Tens of housands of web sites in Australia could be infected with what has been described by Google researchers  as &#8220;drive by&#8221; downloads of malicious code, such as spyware, without a user&#8217;s knowledge.<P>One in 10 web pages scrutinised by search giant Google contained malicious code that could infect a user&#8217;s PC. Researchers from the firm surveyed billions of sites, subjecting 4.5 million pages to &#8220;in-depth analysis&#8221;. <\/P><P>About 450,000 were capable of launching so-called &#8220;drive-by downloads&#8221;, sites that install malicious code, such as spyware, without a user&#8217;s knowledge. A further 700,000 pages were thought to contain code that could compromise a user&#8217;s computer, the team report. <\/P><P>To address the problem, the researchers say the company has &#8220;started an effort to identify all web pages on the internet that could be malicious&#8221;. <\/P><P>Phantom sites <\/P><P>Drive-by downloads are an increasingly common way to infect a computer or steal sensitive information. They usually consist of malicious programs that automatically install when a potential victim visits a booby-trapped website. &#8220;To entice users to install malware, adversaries employ social engineering,&#8221; wrote Google researcher Niels Provos and his colleagues in a paper titled The Ghost In The Browser. <\/P><P>Avoiding attacks&nbsp; <\/P><P>&#8220;The user is presented with links that promise access to &#8216;interesting&#8217; pages with explicit pornographic content, copyrighted software or media. A common example are sites that display thumbnails to adult videos.&#8221; The vast majority exploit vulnerabilities in Microsoft&#8217;s Internet Explorer browser to install themselves. <\/P><P>Some downloads, such as those that alter bookmarks, install unwanted toolbars or change the start page of a browser, are an annoyance. But increasingly, criminals are using drive-bys to install keyloggers that steal login and password information. Other pieces of malicious code hijack a computer turning it into a &#8220;bot&#8221;, a remotely controlled PC. <\/P><P>Drive-by downloads represent a shift away from traditional methods of infecting a computer, such as spam and email attachments. <\/P><P>Attack plan <\/P><P>As well as characterising the scale of the problem on the net, the Google study analysed the main methods by which criminals inject malicious code on to innocent web pages. <\/P><P>&nbsp;<BR>Spam e-mails are a common way to infect a computer It found that the code was often contained in those parts of the website not designed or controlled by the website owner, such as banner adverts and widgets. <\/P><P>Widgets are small programs that may, for example, display a calendar on a webpage or a web traffic counter. These are often downloaded from third-party sites. The rise of web 2.0 and user-generated content gave criminals other channels, or vectors, of attack, it found. <\/P><P>For example, postings in blogs and forums that contain links to images or other content could unwittingly infect a user. The study also found that gangs were able to hijack web servers, effectively taking over and infecting all of the web pages hosted on the computer. <\/P><P>In a test, the researchers&#8217; computer was infected with 50 different pieces of malware by visiting a web page hosted on a hijacked server. <\/P><P>The firm is now in the process of mapping the malware threat. Google, part of the StopBadware coalition, already warns users if they are about to visit a potentially harmful website, displaying a message that reads &#8220;this site may harm your computer&#8221; next to the search results. <\/P><P>&#8220;Marking pages with a label allows users to avoid exposure to such sites and results in fewer users being infected,&#8221; the researchers wrote. <\/P><P>However, the task will not be easy, they say.&nbsp; &#8220;Finding all the web-based infection vectors is a significant challenge and requires almost complete knowledge of the web as a whole,&#8221; they wrote. <BR><\/P><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tens of housands of web sites in Australia could be infected with what has been described by Google researchers  as &#8220;drive by&#8221; downloads of malicious code, such as spyware, without a user&#8217;s knowledge.<\/p>\n","protected":false},"author":74,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"gallery","meta":{"footnotes":""},"categories":[28,27],"tags":[],"class_list":["post-83254","post","type-post","status-publish","format-gallery","hentry","category-archive","category-internet","post_format-post-format-gallery"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Drive By Code Infecting Web Sites Say Google - Smart Office<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Drive By Code Infecting Web Sites Say Google - Smart Office\" \/>\n<meta property=\"og:description\" content=\"Tens of housands of web sites in Australia could be infected with what has been described by Google researchers as &quot;drive by&quot; downloads of malicious code, such as spyware, without a user&#039;s knowledge.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/\" \/>\n<meta property=\"og:site_name\" content=\"Smart Office\" \/>\n<meta property=\"article:published_time\" content=\"2017-07-04T05:36:26+00:00\" \/>\n<meta name=\"author\" content=\"Wire Service\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Wire Service\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/\"},\"author\":{\"name\":\"Wire Service\",\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/#\/schema\/person\/db04f2169f78c1cf4963a220b77f3b56\"},\"headline\":\"Drive By Code Infecting Web Sites Say Google\",\"datePublished\":\"2017-07-04T05:36:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/\"},\"wordCount\":607,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/#organization\"},\"articleSection\":[\"Archive\",\"Internet\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/\",\"url\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/\",\"name\":\"Drive By Code Infecting Web Sites Say Google - Smart Office\",\"isPartOf\":{\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/#website\"},\"datePublished\":\"2017-07-04T05:36:26+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Drive By Code Infecting Web Sites Say Google\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/#website\",\"url\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/\",\"name\":\"Smart Office\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/#organization\",\"name\":\"Smart Office\",\"url\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-content\/uploads\/2025\/07\/Smart-Office-Logo-Final-Yellow-1_page-0001.jpg\",\"contentUrl\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-content\/uploads\/2025\/07\/Smart-Office-Logo-Final-Yellow-1_page-0001.jpg\",\"width\":1359,\"height\":477,\"caption\":\"Smart Office\"},\"image\":{\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/#\/schema\/person\/db04f2169f78c1cf4963a220b77f3b56\",\"name\":\"Wire Service\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g\",\"caption\":\"Wire Service\"},\"url\":\"https:\/\/staging.strixdevelopment.net\/smartoffice\/author\/wire-service\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Drive By Code Infecting Web Sites Say Google - Smart Office","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/","og_locale":"en_US","og_type":"article","og_title":"Drive By Code Infecting Web Sites Say Google - Smart Office","og_description":"Tens of housands of web sites in Australia could be infected with what has been described by Google researchers as \"drive by\" downloads of malicious code, such as spyware, without a user's knowledge.","og_url":"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/","og_site_name":"Smart Office","article_published_time":"2017-07-04T05:36:26+00:00","author":"Wire Service","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Wire Service","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/#article","isPartOf":{"@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/"},"author":{"name":"Wire Service","@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/#\/schema\/person\/db04f2169f78c1cf4963a220b77f3b56"},"headline":"Drive By Code Infecting Web Sites Say Google","datePublished":"2017-07-04T05:36:26+00:00","mainEntityOfPage":{"@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/"},"wordCount":607,"commentCount":0,"publisher":{"@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/#organization"},"articleSection":["Archive","Internet"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/","url":"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/","name":"Drive By Code Infecting Web Sites Say Google - Smart Office","isPartOf":{"@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/#website"},"datePublished":"2017-07-04T05:36:26+00:00","breadcrumb":{"@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/2017\/07\/04\/drive-by-code-infecting-web-sites-say-google\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/staging.strixdevelopment.net\/smartoffice\/"},{"@type":"ListItem","position":2,"name":"Drive By Code Infecting Web Sites Say Google"}]},{"@type":"WebSite","@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/#website","url":"https:\/\/staging.strixdevelopment.net\/smartoffice\/","name":"Smart Office","description":"","publisher":{"@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/staging.strixdevelopment.net\/smartoffice\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/#organization","name":"Smart Office","url":"https:\/\/staging.strixdevelopment.net\/smartoffice\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/#\/schema\/logo\/image\/","url":"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-content\/uploads\/2025\/07\/Smart-Office-Logo-Final-Yellow-1_page-0001.jpg","contentUrl":"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-content\/uploads\/2025\/07\/Smart-Office-Logo-Final-Yellow-1_page-0001.jpg","width":1359,"height":477,"caption":"Smart Office"},"image":{"@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/staging.strixdevelopment.net\/smartoffice\/#\/schema\/person\/db04f2169f78c1cf4963a220b77f3b56","name":"Wire Service","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"Wire Service"},"url":"https:\/\/staging.strixdevelopment.net\/smartoffice\/author\/wire-service\/"}]}},"_links":{"self":[{"href":"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-json\/wp\/v2\/posts\/83254","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-json\/wp\/v2\/users\/74"}],"replies":[{"embeddable":true,"href":"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-json\/wp\/v2\/comments?post=83254"}],"version-history":[{"count":0,"href":"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-json\/wp\/v2\/posts\/83254\/revisions"}],"wp:attachment":[{"href":"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-json\/wp\/v2\/media?parent=83254"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-json\/wp\/v2\/categories?post=83254"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/staging.strixdevelopment.net\/smartoffice\/wp-json\/wp\/v2\/tags?post=83254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}