NEWS A vulnerability has been found in the Lycos search engine which could lead to the PCs of visitors to the site being infected with malicious code. Security lab CBS Sentry Research found a vulnerability in the search engine which could allow a malicious attacker to redirect unsuspecting surfers to a bogus site, or even run malicious code on the user's machine. The risk is only theoretical but could lead to a serious attack. Once the engine has completed a search, the results page displays a short summary of each site found. This description is gleaned from meta-tags attached to the web page. The tags, often in HTML or JavaScript, allow another script to be embedded within the text fields so the text can hide a program that is automatically executed when the search engine displays the page summary. If the program includes a redirection or some form of malicious code then that will be executed by the browser even before the rest of the page is loaded. CBS said other search engines are expected to be vulnerable as well. Alex Kovach, MD of Lycos UK, said: "We are fully aware that there is an issue with our search engine but we are yet to have any examples of abuse. We are currently developing a filter which will block this type of attack."
Lycos open to malicious attacks
Find more than you bargained for with a web search...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
Defeating spam in enterprise email
Enterprises should expect the onslaught of spam to continue. Botnets aren't going away. Criminal syndicates won't...
-
DDoS attack protection: Five best practice tips
Cybercriminals are smarter, stealthier and more adaptive. Traditional defence methods are no longer able to match the...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




