Jonathan Richards
Enter our Snapshots of Summer photography competition
Computer users were warned of the potential hazards of Google today after the company admitted that criminals had hijacked links displayed in some lists of search results and attempted to install viruses on users' machines.
It was unclear how many people were affected by the attack, which targeted the sponsored links that appear on the right hand side of a page and involved the user being sent to a malicious website before being redirected to their desired destination.
Google would not say which search terms were involved, but according to reports, links associated with some 20 terms had to be dismantled, including the "Better Business Bureau", a US-based consumer organisation similar to Which?.
The offending links were shut down as soon as the problem was discovered on Tuesday, Google said, but the attack will cast doubt on the security of AdWords, the system the company uses to sell the advertisements which make up the bulk of its revenues.
AdWords allows companies to bid to have their link displayed prominently alongside the results thrown up by a particular search term.
In the attack, criminals bought links that appeared to be genuinely associated with search terms but which diverted users to a malicious site that attempted to install malware on their computers.
"The analogy would be if you were Reebok, you'd bid on the keyword 'Nike' and then place an ad that appeared to be a link to Nike but which sent the person searching somewhere else first," a Google spokesman said.
The company which discovered the threat, Exploit Prevention Labs, said that earlier this month it had run a Google search on the phrase "how to start a business".
The top sponsored link appeared to be from AllBusiness.com, a legitimate small business consultancy based in San Francisco, but the hyperlink actually led to a site that attempted to install a password-stealing program known as a "key-logger" on the user's PC.
"This discovery highlights problems facing all sponsored search vendors - how to determine the legitimacy of any individual advertiser, and how to determine whether a redirected link is being used legitimately," Exploit Prevention Labs said.
Computer security experts said that the attack, which was similar to one in 2005 that also targeted AdWords, appeared to be isolated, and affected only users of Windows XP who had not updated the anti-virus software on their machines.
In a statement, Google confirmed that its system had been infiltrated, saying: "This is an issue we’ve taken very seriously and will continue to monitor. We are evaluating our systems to ensure that the appropriate measures are in place to block future attempts."
Graham Cluley, a consultant at the security firm Sophos, said that the incident was indicative of a trend among virus-writers to use websites, rather than e-mail attachments, to spread malicious code.
"For many people Google is the internet, and just as in the past Microsoft's Internet Explorer and Outlook have been targeted, so too is Google becoming increasingly attractive for virus writers to try to exploit," he said.
Google recently reported that its first-quarter profits had risen by 69 per cent to $1 billion (£500 million).
Win a luxury weekend to Newcastle and its neighbour Gateshead, find out more here
Risk, resilience and embracing new technology
Industry sectors news at a glance. Interactive heatmap, video and podcast
Discover the collective power of smart thinking. Submit a solution and be in with a chance to win a Flip MinoHD Camcorder
The inside track on current trends in the charity, not for profit and social enterprise sectors
Everything the Business Traveller needs to know to make a better trip
Make the most of the summer and enter our fabulous photographic competition, you could win a £5000 holiday
Corsica is an island of beauty and contrast, an ideal holiday destination
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
The clever way to lease a new car is with Car leasing made simple™
2009
42,945
2008
71,450
Car Insurance
Not Specified
MI6
UK-based
£60,000
The Environment Agency
Bristol
Up to £90K
Boots
Midlands
OTE £85k
Credit Protection Association
Nationwide Opportunities
Completely London
Luxury Condo's in Manhattan with NYC views
The best new homes in Wimbledon?
Nationwide
Save up to £1,000 per couple with Elite Vacations at the five-star Constance Lemuria Resort
and do the British Isles this Summer.
Save up to 60% with Oxford Hotels and Inns
Try our inspiring luxury holidays to the Indian Subcontinent and South East Asia.
Great offers available
8 fabulous Canadian cities ...you won’t find cheaper
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Property Finder | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.
get linux or a mac...oh..did someone mention that already?
YouBee, Tulsa, OK
Fine, nobody can anticipate the unexpected, but surely you should be prepared to fight back hard and really hard too. Google should be able to trace the hijackers, since they participated in their Adwords program, and should be willing to spend millions not only in pursuing the criminals, but also to set an example of how severe penalties can be when you mess with 800 lbs gorilla. If Google does nothing, criminals will be racing to challenge themselves on how they can injure Google in so many different ways and its customers as well.
Deterrence is the best way for protection. Google should use its lawyers to protect itself and those who trusted Google to use its services. By setting precedent example, the smarter criminals will think twice before committing a crime. After all, wise men learn from other peoples' mistakes, and only fools learn from their mistakes. Sure there will always be a small bunch of fools, but Google would be prepared for them.
Hamada Agha Abu Dhabi UAE
Hamada, Abu Dhabi, UAE
get a linux
steve ballmer, redmond , wa
Google has other problems to with there add words - as a website owner - google are not as honest with there commissions as the press makes them out to be.
I put ad words in place and then had to take them out as I found them not to be honest. I then put back traditional banners.
Google has so much free press on the internet because anyone who writes editorial about google can put banners linking back to google subscriptions of $99 and then whopping 40% commission comes back to the author when a new website owner who after reading the article clicks into google website and submits there details and payments for a google listing.
Nicholas Iles, Oswestry, United Kingdom
Get a Mac.
Scottie, New York, NY
It's better to use another software for users, but we can't stop to use Google service. It searches good. Google have to spend more money to test for robust their software.
Khamidullin Radik, Russia, Kazan,