Weblog entry #250 for simonw
#250
winzipices.cn under counting
Posted by simonw on Fri 9 May 2008 at 13:51
Seems that folk tracking the SQL injection worm are counting the occurrences of "winzipices.cn" on the net by typing it into Google and assuming the first number back reflects the number of infected web pages.
Google don't always return every page in a search, so whilst such a method probably produces a good indication of whether such a worm is widespread, or still spreading, as a guide to the absolute number of compromised pages it is fairly hopeless.
Contrast Google searches for:
"winzipices.cn" (about 12,200) against "winzipices.cn site:com" (about 17,400)
Either way you probably don't want to visit any of the resulting pages.
Anyone know a way to get Google to give us its best guess? Google will of cause always be an underestimate.
Google don't always return every page in a search, so whilst such a method probably produces a good indication of whether such a worm is widespread, or still spreading, as a guide to the absolute number of compromised pages it is fairly hopeless.
Contrast Google searches for:
"winzipices.cn" (about 12,200) against "winzipices.cn site:com" (about 17,400)
Either way you probably don't want to visit any of the resulting pages.
Anyone know a way to get Google to give us its best guess? Google will of cause always be an underestimate.