<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : The Work Buzz</title><link>http://pandalabs.pandasecurity.com/archive/tags/The+Work+Buzz/default.aspx</link><description>Tags: The Work Buzz</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>New Blackhat SEO attack exploits vulnerabilities in Wordpress to distribute rogue antivirus software</title><link>http://pandalabs.pandasecurity.com/archive/New-Blackhat-SEO-attack-exploits-vulnerabilities-in-Wordpress-to-distribute-rogue-antivirus-software.aspx</link><pubDate>Thu, 23 Apr 2009 16:50:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:994</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/994.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=994</wfw:commentRss><description>
&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;Over the past week we have seen a new Blackhat SEO technique  emerge to exploit vulnerabilities in the popular Wordpress blog software.&amp;nbsp; Two of the sites we identified were  TheWorkBuzz.com, a website owned and operated by Career Builder  (CareerBuilder.com), and The Center for International Media Assistance, an  initiative of the National Endowment for Democracy (NED.org). Just like last  week&amp;rsquo;s attack against &lt;a href="http://pandalabs.pandasecurity.com/archive/Targeted-Blackhat-SEO-Attack-against-Ford-Motor-Co_2E00_.aspx"&gt;Ford Motor&lt;/a&gt;, these scams work by misleading search engines  to falsely promote malicious pages to the top of the search results.&amp;nbsp;When a  user visits one of the malicious sites, they are duped into downloading fake  antivirus software.&lt;/p&gt;

&lt;p&gt;You can checkout a video demonstrating how this particular attack  works below:&lt;br /&gt;
  &lt;a href="http://vimeo.com/4288832"&gt;
  &lt;/a&gt;&lt;/p&gt;

&lt;blockquote&gt;&lt;a href="http://vimeo.com/4288832"&gt;&lt;img alt="press play" border="0" height="382" src="http://support.us.pandasecurity.com/blog/pressplay.png" width="506" /&gt;&lt;/a&gt;&lt;/blockquote&gt;

&lt;p&gt;Both attacks involve a vulnerability in an older version of  Wordpress, which allows the /wp-includes/ folder of the software to house  thousands of malicious redirectors.&amp;nbsp;&amp;nbsp;  Exact details of the specific vulnerability are not yet known, but we  have contacted both site owners and the security team at Wordpress to get  clarification.&amp;nbsp; &lt;/p&gt;

&lt;p&gt;In the first case involving the Center for International  Media Assistance website, we uncovered over 13,330 words used in the Blackhat  SEO attack.&amp;nbsp; We took all the terms and  threw them into a Tag Cloud generator to see how they were targeting the CIMA  viewers.&amp;nbsp; Here&amp;rsquo;s what we found:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://support.us.pandasecurity.com/blog/tagcloud.jpg"&gt;&lt;img alt="Tag Cloud Thumbnail" border="0" src="http://support.us.pandasecurity.com/blog/tagcloud_small.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Song&lt;/strong&gt; - Appeared 1303  times &lt;br /&gt;
  &lt;strong&gt;Software &lt;/strong&gt;- Appeared 879 times&lt;br /&gt;
  &lt;strong&gt;Free &lt;/strong&gt;- Appeared 244 times&lt;br /&gt;
  &lt;strong&gt;Lyrics &lt;/strong&gt;- Appeared 210 times&lt;/p&gt;

&lt;p&gt;Cyber-criminals have chosen Rogue Anti-Malware as their  primary method of payment because it has become easier for them to make money  by affiliate systems and utilizing these types of attacks.&amp;nbsp; It&amp;rsquo;s no wonder why we have seen more Rogue  detections in the first quarter of 2009 then all of 2008. As you can see from  the chart below,&amp;nbsp; PandaLabs predicts that  incidents of rogue AV scams will grow 100 percent quarter over quarter through the  end of Q3.&amp;nbsp; &lt;/p&gt;

&lt;p&gt;&lt;img alt="Rogue AV Growth" src="http://support.us.pandasecurity.com/blog/rogueav_growth.png" /&gt;&lt;/p&gt;

&lt;p&gt;Remember, It&amp;#39;s just as important to update your web applications as it is to update your operating system. If you use Wordpress as a platform for your blog or website, then I recommend viewing the &lt;a href="http://codex.wordpress.org/Hardening_WordPress"&gt;official hardening guide.&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=994" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/SEO/default.aspx">SEO</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat/default.aspx">Blackhat</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Video/default.aspx">Video</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/The+Work+Buzz/default.aspx">The Work Buzz</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogue+Anti-malware/default.aspx">Rogue Anti-malware</category></item></channel></rss>