On GameSpot: The opening movie for WoW: Lich King
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto, News.com
Posted on ZDNet News: Jul 18, 2006 7:42:00 PM

A worm is targeting MySpace users, compromising their "About me" pages and infecting visitors to them, Symantec has warned.

When a logged-in MySpace user goes to another member's "About me" page affected by the ACTS.Spaceflash worm, they are quietly redirected to a URL that holds a malicious Macromedia Flash file, the security company said in an advisory on Spaceflash Tuesday. That file, in turn, will replace the visitor's own "About me" page with one that is compromised.

"It's an annoyance, at this point, for users, but the capability exists where it can lead to malicious actions and steal sensitive information," said Dean Turner, senior manager of Symantec, which currently rates the Spaceflash threat as low.

Figures were not readily available on the number of MySpace users who were infected by the worm, Turner said.

The worm takes advantage of the way Adobe Systems' Macromedia Flash technology, used to display media on the Internet, handles its action scripting for movies and music.

"Adobe recognized this vulnerability in Flash 8 and fixed it in its latest version, which is why we're urging all members to upgrade to Flash 9," Hemanshu Nigam, the chief security officer of MySpace, said in a statement.

Symantec is advising MySpace users to disinfect their "About me" page by deleting a specific line of code, or to disable their use of JavaScript on MySpace.com to mitigate the problem.

Content uploaded to MySpace and other social-networking sites needs to be validated and vetted by the Web site operators to ensure users do not infect each other, Turner said.

The Spaceflash worm is not the first to hit MySpace. Last fall, it was hit by the Samy worm, which added a million users to the friends list of the worm's author.

  • Talkback
  • Most Recent of 16 Talkback(s)
Message has been deleted.
(Read the rest)
Posted by: yogeee Posted on: 07/20/06  (Edited: 10/25/2006 @ 07:14) You are currently: Logged In | Log out
It is so nice for me that I didn't have a MySpace account... Grayson Peddie   | 07/18/06
Squid Anyone? ibabadur1   | 07/18/06
That's the reason I never care about MySpace. Grayson Peddie   | 07/18/06
Initiatives abound, supporters should make a showing yogeee   | 07/18/06
ooops sorry here listenup.org more specifically yogeee   | 07/18/06
MYSPACE uses Microsoft II s version 6.0 servers . Intellihence   | 07/18/06
What does that have to do... kckn4fun   | 07/19/06
Probably a bit of both... Justin James   | 07/19/06
Good. Secure mharr   | 07/19/06
Don't you know it's gross to share germs? mroonie   | 07/19/06
Adobe's Flash worm nuking MySpace users Unknown   | 07/19/06
Hell's Bells... znewt   | 07/19/06
Message has been deleted. yogeee   | 07/20/06
Sooo many difficulties with Myspace Nathank@...   | 07/19/06
Are MSN spaces any safer? tygeverink@...   | 07/19/06
Re: myspace worm lwvirden   | 07/26/06

What do you think?

advertisement
advertisement
advertisement
Click Here