UMBC ebiquity research group Building intelligent systems in open, heterogeneous, dynamic, distributed environments
29 August 2008, 01:59:19 EDT  
Splogs are phishing and infecting visitors with trojans

Splogs are phishing and infecting visitors with trojans

Tim Finin, 1:00pm 18 March 2007

Splogs send visitors to phishing sites like this oneThe Internet security firm Fortinet has issued an advisory Malicious Code Appears on Blogger.com that identifies new splogs intended to expose visitors to malware. The advisory gives two examples found on blogger. In one, scripts are used to redirect visitors to Pharmacy Express, a phishing site. Another example given is of a site devoted to the Honda CR450 that infects visitors with the Javascript Wonka Trojan. Stories on the alet have been written by PC World and cnet.

To date, the splogs we have studied were created to host advertisements and/or raise the pagerank of affiliated sites. It’s inevitable, I think, that blogs will become a vehicle for other uncooperative, unsavory or outright illicit behavior. Their current software and service infrastructure make blogs the easiest and cheapest way to create web sites and populate them with a stream of fresh content. It’s nature, red in tooth and claw, after all.

Leave a Reply






UMBC