Jump to content

Recommended Posts

  • ExTS Admin
Posted

Zscaler warns of fake AV threat.

 

Security firm Zscaler has discovered nearly three million phony YouTube pages all pushing unsuspecting users towards fake anti-virus (AV) downloads.

 

The firm’s network security engineer, Julien Sobrier, explained in a blog post that the pages, which have all been indexed by Google, can be found by searching for ‘Hot Video’.

 

“The fake YouTube video page is covered by an invisible Flash layer and the Flash object automatically redirects the user to a fake AV page,” he explained.

 

“If the user has Flash disabled, the page becomes harmless. The URL of the Flash file, hosted on a different domain, is obfuscated with Javascript.”

 

The HTML code on the pages includes links to legitimate sites such as Flickr.com, in order to make sure the content is indexed by search engines, he added.

 

The fake AV software is hosted on several domains and, worryingly, are undetected by most security tools. Google Safe Browsing does not block 90 per cent of these pages in Firefox while the detection rate among AV vendors is only 11 per cent, Sobrier explained.

 

“This type of threat is different from the usual Blackhat spam SEO: the same content is shown to the user and to the search engine, therefore the page can be accessed directly, without clicking on search engine results,” he added.

 

“Because the ‘Hot Video’ pages use both obfuscated Javascript and Flash, it is harder for security scanners to detect them.”

 

 

Source:

Three million bogus YouTube pages discovered - V3.co.uk - formerly vnunet.com

Member of:

UNITE

  • Replies 0
  • Created
  • Last Reply

Top Posters In This Topic

Popular Days

Top Posters In This Topic

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...