usatoday.com

Attackers booby-trap searches at top Web sites

Updated at 11:22 a.m. PDT Saturday to include a comment from Wal-Mart.

A million search queries have been "poisoned" at dozens of well-known Web sites over the past several weeks, according to security analyst Dancho Danchev.

Attackers are using programming errors to hijack keyword searches by automatically attaching malicious HTML code to specific search queries. Unwitting visitors who type in the selected key words while performing a search at the affected sites are then redirected to booby-trapped Web sites.

This is where the attackers attempt to install malware onto the victims' computers.

Among some of the … Read more