You are here: silicon.com > Software > Malware

Malware

MySpace worm goes phishing

Malicious video infects user profiles...

Tags: myspace, phishing, worm

By Joris Evers

Published: 5 December 2006 08:30 GMT

A malicious video on MySpace.com pages changes people's profiles when played, embedding itself and adding links to fraudulent websites, experts have warned.

The video is a rigged QuickTime file that exploits a MySpace vulnerability and support for JavaScript in Apple's embedded media player, web security company Websense said in an alert posted last week.

When played by a MySpace user, the video adds itself to the user's MySpace page and replaces the links on the user's profile with links to phishing websites, Websense said.

A MySpace representative said she could not immediately comment on the worm.

The a popular social-networking website, owned by News Corp, is estimated to have more than 70 million registered users. The worm exploits a common type of web vulnerability called a cross-site scripting flaw in the site along with a feature called HREF track in QuickTime that has legitimate uses but can also be abused, experts said.

Mikko Hypponen, chief research officer at security company F-Secure, wrote in a blog posting: "It seems that we have a MySpace worm on our hands, using a malicious QuickTime MOV file to spread."

The rigged QuickTime movie includes some JavaScript code that will be run automatically when an infected page is viewed with Internet Explorer, Hypponen wrote. This snippet of code modifies the user's MySpace profile. "After that, everybody who visits your MySpace profile gets hit too," he wrote.

The same happens when viewing an infected page with Firefox, according to a reader of silicon.com sister site CNET News.com who had his MySpace profile compromised.

The object of the attack appears to get people to visit the phishing websites. These pages are crafted to look like MySpace log-in pages and prompt users to enter their MySpace credentials, according to F-Secure.

This is not the first threat to hit MySpace. Miscreants have exploited the popularity of the website before to steal personal information and spread adware. Also, some MySpace users have exploited weaknesses in the site to boost their fame.

Experts have warned that as websites are becoming more interactive, security needs to be to be top-of-mind, not an afterthought. The development momentum for many sites is all about features, with protections being neglected, they have said.

An infected MySpace page will include links to the fraudulent websites and a blue navigation bar that is not typically found on MySpace pages, according to researchers at FaceTime Security Labs.

Chris Boyd, director of malware research at FaceTime, wrote in a blog post: "If this is the case, you will need to clean out your profile and check if any of your friends have also been infected."

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
SEO Specialist - Multilingual - City - Finance - Competitive

Operating in the financial and betting industries, my key client is looking to take on an SEO specialist to focus on their numerous high profile, ...

Web Designer , great design work Up to Open

Please apply immediately with URL links. In your role as a web designer you will be working with a team of designers in developing websites, making ...

Web Developer - Kent

The role requires taking day to day updates of clients websites, building web pages, extending sites, content input, building emails etc. You are ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: