Risk
2/1/2009
08:40 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Google Typo Causes Malware Warning Misfire

Millions of confused Google users encountered a warning page Saturday morning.

A misplaced "/" on Saturday morning prompted Google's malware warning system to flag every search-results link as dangerous.

The snafu lasted from between 6:30 a.m. PST and 7:25 a.m. PST. Confronted by a warning page placed between the flagged link and the destination site, millions of confused Google users followed an explanatory link that led to StopBadware.org, the organization that helps Google establish criteria for designating a site malicious. The surge of traffic led to what StopBadware likened to a "denial-of-service attack" and proved to be more than the site could handle, taking the site offline temporarily.

In a blog post shortly after the incident, Marissa Mayer, Google's VP of search products and user experience, apologized and attributed the problem to human error.

"Google flags search results with the message 'This site may harm your computer' if the site is known to install malicious software in the background or otherwise surreptitiously," she said. "We do this to protect our users against visiting sites that could harm their computers. We maintain a list of such sites through both manual and automated methods. We work with a non-profit called StopBadware.org to come up with criteria for maintaining this list, and to provide simple processes for webmasters to remove their site from the list. We periodically update that list and released one such update to the site this morning. Unfortunately (and here's the human error), the URL of '/' was mistakenly checked in as a value to the file and '/' expands to all URLs."

The mistake also rippled through Google's Gmail service, which uses the same filtering system for identifying incoming e-mail as spam. On Saturday, Rishi Chandra, senior product manager for Google Apps, said in a blog post that the company was working on an automated fix to move legitimate messages that had been erroneously labeled spam back into Gmail users' in-boxes. He advises those expecting critical messages to check their Gmail spam folders while Google worked a way to refilter its users' e-mail. As of Sunday, Chandra said that the fix had been implemented but he cautioned that users should still check messages identified as spam that arrived between 6:00 a.m. and 8:00 a.m. PST on Saturday.

Ironically, Google's paranoid vision of a Web where every site is dangerous isn't far from the way security companies see things. An IBM X-Force security report planned for release on Monday warns that Web vulnerabilities are at an all-time high and that hackers have become adept at compromising legitimate sites. Given the speed at which malicious code can appear and disappear from the Web, something noted by security researchers at AVG Technologies, it appears that a great many sites that aren't marked as malicious should be. Perhaps Google's exaggeration of online malice will look overly conservative in a year or two.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4448
Published: 2014-10-22
House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.

CVE-2014-4449
Published: 2014-10-22
iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-4450
Published: 2014-10-22
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.

CVE-2012-5242
Published: 2014-10-21
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

CVE-2012-5243
Published: 2014-10-21
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.