
Find more than you bargained for with a web search...
By Pia Heikkila
Published: 31 July 2001 17:02 GMT
A vulnerability has been found in the Lycos search engine which could lead to the PCs of visitors to the site being infected with malicious code.
Security lab CBS Sentry Research found a vulnerability in the search engine which could allow a malicious attacker to redirect unsuspecting surfers to a bogus site, or even run malicious code on the user's machine. The risk is only theoretical but could lead to a serious attack.
Once the engine has completed a search, the results page displays a short summary of each site found. This description is gleaned from meta-tags attached to the web page. The tags, often in HTML or JavaScript, allow another script to be embedded within the text fields so the text can hide a program that is automatically executed when the search engine displays the page summary.
If the program includes a redirection or some form of malicious code then that will be executed by the browser even before the rest of the page is loaded. CBS said other search engines are expected to be vulnerable as well.
Alex Kovach, MD of Lycos UK, said: "We are fully aware that there is an issue with our search engine but we are yet to have any examples of abuse. We are currently developing a filter which will block this type of attack."
Optimisers, and Web Developers • Analyze customer Web sites and provide well-defined strategies for search engine improvement. Leverage skills ...
SEO / Search Engine OptimisationA web agency in Colchester requires an SEO specialist to come on board and provide Search Engine Optimisation for a ...
Engine Marketing Specialist Engine Marketing Specialist required by leading SEM agency based in Lancashire. s, we are looking for a search engine ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you
Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business