PDFPrintE-mail

Google Sites sending spam as CAPTCHA gets pwned

Business IT - Security

According to the latest MessageLabs Intelligence Report, the Google Sites CAPTCHA spambot defences have been compromised by spammers...

The MessageLabs Intelligence Report for July 2008 reveals that spammers are looking towards Google Sites to spread their wares. This follows on from previous spam attacks directed at Google Docs, Google Pages and Google Calendar.

Researchers look at it as being just the latest in a continuing trend that targets Google's hosted applications in order to exploit the brand trust to distribute spam and malware. There are two reasons why Google Sites has been targeted, they say:

Firstly, it allows the novice to create a web page that comprises entirely of a string of random letters and numbers with relative ease. This results in a URL that is far more difficult to block than most when using bog-standard signature-based anti-spam tools.

Secondly, and a lot more worryingly so, is the indication that the 'Completely Automated Public Turing Test to Tell Computers and Humans Apart' or CAPTCHA entry validation system has been pwned.

"Google Sites is yet another way that spammers have programmatically defeated CAPTCHA mechanisms" Mark Sunner, Chief Security Analyst at MessageLabs insists "While Google Sites spam accounts for only 1 percent of all spam currently, we anticipate that this technique's popularity will rival that of its predecessors, Google Docs, Calendar and Pages spam. If this is the case, then we may see spam levels increase in the months ahead." 

Not the best of news, it has to be said. But then neither is the fact that the number of new malicious websites blocked each and every day in July increased by a whopping 91 percent from 2,076 compared to June. This takes the daily total up to a rather depressing average of 3,968 new sites.

So what is to blame? Other than the obvious dirty scumbag spammers answer, is the equally obvious SQL injection attacks one. "An emerging theme for threats this month seems to be new variations on old attack methods" Sunner told us.

Want to know which country is the most spammed in the world? Find out on page 2...

CONTINUES



SPONSORED ANNOUNCEMENTS

Top Five Tips for Securing your Business Reputation from AVG (AU/NZ)

Wednesday, 10 March 2010

There have been recent reports of how a Twitter scam has affected some well known UK politicians, issuing embarrassing Tweets from their personal accounts. Whilst these headlines may seem amusing, Lloyd Borrett, the Marketing Manager at AVG (AU/NZ), says it is worth considering the potential impact of this type of scam on your business reputation.

Featured IT jobs

BI/DW Analyst (S9) BI/DW Analyst <...
Skills Tags:   Crystal Reports  Development  Reporting  SAS  SQL  SQL Server
Senior Systems Engineer - Melbourne Senior Linux Systems Engineer Opportunity wor...
Skills Tags:   Agile  IT  Linux
A large Federal Government organisation with offices in Adelaide is seeking a SAS Pr...
Skills Tags:   IT  SAS  Scripting  Support
My client is a large Investment Bank with offices in Sydney's CBD. </...
Skills Tags:   IT  Security  Sybase  Unix

Editors Picks

Stories you may have missed 

What iTWire offers for free

E - mail News SMS Headlines Desktop Alerts News Feeds Job Alerts Technology Events Press-Releases