PageRank is another Google-based method aimed at ruining corporate reputations. It consists of algorithms developed by Google to measure quantitatively the relevance or importance of web pages on a scale of 0 to 10. A company’s PageRank usually represents its popularity; if the value is high, it is usually considered to be a reliable source accessed by many important sites.
Google is currently penalizing companies who exchange links and artificially try to increase PageRank. Attackers are exploiting this to insert penalized links on legitimate web pages. This way, they get the site to be penalized, its PageRank to decrease, and thereby damage its reputation.
Other ways of attacking a reputation
CastleCops is a volunteer security community focused on making the Internet a safer place. Its free services include malware and rootkit cleanup, malware and phishing research, and malware and hash databases.
CastleCops accepts donations via PayPal. Attackers took advantage of this to begin a campaign aimed at discrediting CastleCops. They stole PayPal users’ passwords using Trojans and phishing techniques, and made several donations to CastleCops. When users realized someone had sent their money to CastleCops, they blamed CastleCops for the fraud. Consequently, CastleCops was forced to return all the money, and invest in resources to manage all the complaints and requests. CastleCops’ reputation was undoubtedly damaged.
Most of the methods described above are essentially malware-based. For example, botnets are used to carry out distributed denial of service attacks and to launch spam that contains false information to ruin companies’ images. Most defacements also use automated attack tools. In the case of Google, malware is also used to automate the insertion of links and spam on 2.0 websites that allow users to add content. In the case of CastleCops, Trojans were used to steal PayPal users’ credentials.
There are numerous scenarios in which viruses, Trojans and other malware-types can damage a company’s reputation. In 2004, even Google was affected by the MyDoom worm which disabled many of its servers for several hours. Worse still, the search engine underwent the attack hours before being floated on the stock market. Other search engines such as Altavista, Yahoo! and Lycos were also affected by the worm.
Phishing techniques, which are still as popular as ever, can also damage companies. These attacks are critical for banks, since they cause financial losses and strike fear in users. In the same way, specially-crafted Trojans (mainly banker Trojans) have become one of the worst Internet threats. The main danger lies in the fact they are designed to specifically affect certain entities, and in many cases, operate totally invisibly and when users access their online bank, their access credentials are sent to hackers. In 2006, Trojans accounted for 53 percent of all new malware created, and 20 percent of these were banker Trojans. During 2007, there have already been over 40 percent more attacks than in the whole of 2006.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.