By Keith Regan TechNewsWorld Part of the ECT News Network
12/05/06 1:35 PM PT
MySpace was forced to shut down hundreds of user profile pages after a combination worm and phishing attack struck the site over the weekend. On the pages hit by the attack, the worm converted legitimate links to those that brought users to a phishing site that attempted to obtain personal information, including their MySpace username and password.
Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!
Leading social networking site MySpace was forced to shut down hundreds of user profile pages after a combination worm and phishing attack struck the site over the weekend.
The worm, discovered late last week, targeted the Javascript support code associated with Apple's (Nasdaq: AAPL) QuickTime player in conjunction with a vulnerability in MySpace itself. MySpace enables users to embed the QuickTime video and audio player into their personal pages.
On the pages hit by the attack, the worm converted legitimate links to those that brought users to a phishing site that attempted to obtain personal information, including their MySpace username and password. Having that information could enable a third party to pose as a MySpace user and perform additional fraudulent activities.
MySpace did not respond to requests for comment. Also, it was not clear whether any MySpace users had fallen victim to the phishing scam, but Websense Security Labs, which first reported the attack over the weekend, said MySpace had apparently removed all profiles that had been affected by the attack by late Monday. All but one of the phishing sites had been shut down as well, Websense said.
The attacks are not the first to target MySpace users, and the site will likely find itself more in the crosshairs of hackers and malicious code writers.
Top of the Charts
For one thing, the site is now among the most popular on the Internet -- Hitwise reported it surpassed Yahoo (Nasdaq: YHOO) as the most visited site in the U.S. over the summer.
In addition, the linked-together nature of MySpace, which encourages users to build out their network of "friends" by creating links with others they don't yet know, may lend itself to the type of social engineering required to make phishing attacks effective.
Websense noted that the latest attack exploited a vulnerability in MySpace itself that was widely announced two weeks ago through the Full Disclosure mailing list.
Users had their profiles infected by viewing a QuickTime video that contained the malicious code. Links on their page were then replaced with links to the phishing site and the video itself was loaded onto the page.
In June, Websense warned of a phishing attack aimed at MySpace users. In that case, users were receiving instant messages purporting to be from fellow members.
Instead, the messages contained links to a phishing site that was designed to look like the main MySpace home page. If users logged in through the site, the phishing site captured their usernames and passwords.
Open Doors, Let in Worms?
Some security experts believe the reams of user-generated content that is the bulwark of so-called Web 2.0 applications make it easier for some types of viruses to be spread, and may even make such sharing sites more common vehicles for spreading viruses and other malware than e-mail .
Last month, the popular Wikipedia, which lets users update entries, was hacked, allowing a page loaded with malicious code to be added to the site.
"A big part of making these types of attacks, especially phishing attacks, effective is the social engineering that goes into it," Sophos Senior Technology Consultant Graham Cluley told TechNewsWorld. "The MySpace brand has quickly become a household name. It was only a matter of time before spammers jumped on its popularity for illegal purposes."
Cluley noted that a spam attack in October tried to direct recipients to a fake MySpace page under the guise of a free music offer, and that in early 2005, a New York teenager was arrested for spamming 1.5 million users of the then-nascent MySpace, suggesting malicious code writers and phishers have long recognized the opportunity the MySpace user base represents.
"Any company on the Web that sees the kind of growth MySpace has experienced is bound to become a target," he added.
YouTube Strikes Exclusive Content Deal With Verizon November 28, 2006
Starting in December, Verizon Wireless V Cast subscribers will be able to watch a limited selection of videos available on the YouTube video-sharing site. In addition, V Cast users will be able to upload their own videos to YouTube on-the-fly. Content-licensing deals such as this could provide YouTube with an important source of revenue.
Related Stories
Universal Seeks Millions in MySpace Suit November 20, 2006
In a lawsuit filed against MySpace.com, Universal Music Group is seeking $150,000 for each instance of copyright infringement claimed, which could add up to millions of dollars. Universal is accusing the popular networking site of letting its users upload videos and songs illegally.
MySpace Inks Deal to Block Copyright Infringers October 30, 2006
MySpace.com is licensing technology to block unauthorized copyrighted music audio recordings from being posted on its site. "MySpace is staunchly committed to protecting artists' rights -- whether those artists are on major labels or are independent acts," said Chris DeWolfe, CEO and co-founder of MySpace.
MySpace Founder Seeks Probe of Sale to News Corp. October 06, 2006
MySpace founder Brad Greenspan claimed that e-mails and other information he has posted to the Freemyspace.com Web site show that the deal with News Corp. was consummated despite belief at the time that the company was worth more. He said an investigation would show the sale was "one of the largest merger and acquisition scandals in U.S. history."
Related News Alerts
More by Keith Regan
Yahoo Slaps Fresh Coat of Gloss on Microsoft Deal Defense June 30, 2008
With its shareholders meeting set to take place in less than five weeks, Yahoo has put together a 32-page presentation, emphasizing why the investors should vote to keep the current board in place. The company also reiterated why it chose to partner with Google instead of letting Microsoft buy part of it.
French Court Stings eBay With $63M Judgment Over Knockoff Sales June 30, 2008
eBay is planning to appeal a ruling by a French court that ordered it to pay $63 million to the luxury goods maker Louis Vuitton Moet Hennessey. The court also barred the online auctioneer from selling four brands of perfume on its Web sites accessible in France.
New Auto Loan Leads Marketplace Shifts Into Drive June 30, 2008
Reply.com's move into the auto finance market is a logical one the company, as automotive advertising spending is moving online in increasingly greater amounts. The company is partnering with the Detroit Trading Company to create a massive repository of auto finance leads online.