On mySimon: Josh Jakus Wool Handbags
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Dec 4, 2006 8:50:00 PM

A malicious video on MySpace.com pages changes people's profiles when played, embedding itself and adding links to fraudulent Web sites, experts have warned.

The video is a rigged QuickTime file that exploits a MySpace vulnerability and support for JavaScript in Apple Computer's embedded media player, Web security firm Websense said in an alert posted on Friday.

When played by a MySpace user, the video adds itself to the user's MySpace page and replaces the links on the user's profile with links to phishing Web sites, Websense said. Phishing sites are fraudulent sites that attempt to trick people into giving up sensitive information such as log-in credentials.

A MySpace representative on Monday said she could not immediately comment on the worm.

MySpace, owned by News Corp., is a popular social-networking Web site that is estimated to have more than 70 million registered users. The worm exploits a common type of Web vulnerability called a cross-site scripting flaw in the site along with a feature called HREF track in QuickTime that has legitimate uses but can also be abused, experts said.

"It seems that we have a MySpace worm on our hands, using a malicious QuickTime MOV file to spread," Mikko Hypponen, chief research officer at security company F-Secure, wrote in a blog posting Saturday.

The rigged QuickTime movie includes some JavaScript code that will be run automatically when an infected page is viewed with Internet Explorer, Hypponen wrote. This snippet of code modifies the user's MySpace profile. "After that, everybody who visits your MySpace profile gets hit too," he wrote.

The same happens when viewing an infected page with Firefox, according to a CNET News.com reader who had his MySpace profile compromised.

The object of the attack appears to get people to visit the phishing Web sites. These pages are crafted to look like MySpace log-in pages and prompt users to enter their MySpace credentials, according to F-Secure.

This is not the first threat to hit MySpace. Miscreants have exploited the popularity of the Web site before to steal personal information and to spread adware. Also, some MySpace users have exploited weaknesses in the site to boost their fame.

Experts have warned that as Web sites are becoming more interactive, security needs to be to be top-of-mind, not an afterthought. The development momentum for many sites is all about features, with protections being neglected, they have said.

An infected MySpace page will include links to the fraudulent Web sites and a blue navigation bar that is not typically found on MySpace pages, according to researchers at FaceTime Security Labs.

"If this is the case, you will need to clean out your profile and check if any of your friends have also been infected," Chris Boyd, director of malware research at FaceTime, wrote in a blog post.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 23 Talkback(s)
doh: important information for your health
regarding that last line of the article...

when you "check if any of your friends have also been infected" be sure to check with them in person, over the phone, via txt msg, telepathy, w/e. thi... (Read the rest)
Posted by: mindilator@... Posted on: 12/06/06 You are currently: a Guest | | Terms of Use
This is why I refuse to use QuickTime  NonZealot | 12/04/06
Just prove it *Again*  Mectron | 12/04/06
Its not a quicktime bug  Stuka | 12/04/06
Not a flaw in Internet Explorer  PB_z | 12/04/06
Then why is Apple fixing it?  NonZealot | 12/05/06
Well then, to be fair you should ...  Len Rooney | 12/04/06
Then I guess I'm fair!  NonZealot | 12/04/06
odd slant  birdofire@... | 12/04/06
geezz... time to get back on your meds... conspiracy theory boy!  doctorSpoc | 12/05/06
only windoze is affected  Linux Geek | 12/04/06
I'm so glad  TonyMcS | 12/04/06
More lies, more ********, more ignorance  uberpinguin | 12/04/06
And you're saying  John Zern | 12/04/06
Ok then...  Badgered | 12/05/06
So if he's wrong, are you supporting Linux Geek  Boot_Agnostic | 12/06/06
Must have gotten ZDNet too  j.m.galvin | 12/04/06
MySpace.com blocked!  Grayson Peddie | 12/04/06
nothing on firefox too  RIAAsucks | 12/04/06
Please don''t give people ideas!  timera9 | 12/04/06
Linux Fuel  **owly** | 12/04/06
Could just as easily happen on Linux  PB_z | 12/04/06
QuickTime, well that'll limit the spread  Boot_Agnostic | 12/06/06
doh: important information for your health  mindilator@... | 12/06/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here