
Find more than you bargained for with a web search...
By Pia Heikkila
Published: 31 July 2001 17:02 BST
A vulnerability has been found in the Lycos search engine which could lead to the PCs of visitors to the site being infected with malicious code.
Security lab CBS Sentry Research found a vulnerability in the search engine which could allow a malicious attacker to redirect unsuspecting surfers to a bogus site, or even run malicious code on the user's machine. The risk is only theoretical but could lead to a serious attack.
Once the engine has completed a search, the results page displays a short summary of each site found. This description is gleaned from meta-tags attached to the web page. The tags, often in HTML or JavaScript, allow another script to be embedded within the text fields so the text can hide a program that is automatically executed when the search engine displays the page summary.
If the program includes a redirection or some form of malicious code then that will be executed by the browser even before the rest of the page is loaded. CBS said other search engines are expected to be vulnerable as well.
Alex Kovach, MD of Lycos UK, said: "We are fully aware that there is an issue with our search engine but we are yet to have any examples of abuse. We are currently developing a filter which will block this type of attack."
In addition to our flagship site www.shopzilla.com.co.uk, .de, .fr) and well known BizRate brand (www.bizrate.com), Shopzilla also powers shopping ...
The role with will be focussing on Search Engine Marketing (SEM) and Search Engine Optimisation (SEO) technologies and will be focussed on API. ...
While we're still committed to building the perfect search engine, our work here goes well beyond delivering accurate search results. Our work at ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...