Email us! Subscribe to Liquidmatrix!

MySpace XSS QuickTime Worm

The folks at Websense have confirmed the existence of a worm that is spreading through MySpace.com. The worm is apparently exploiting the QuickTime player.

The vulnerabilities are being used to replace the legitimate links on the user’s MySpace profile with links to a phishing site.

Once a user’s MySpace profile is infected (by viewing a malicious embedded QuickTime video), that profile is modified in two ways. The links in the user’s page are replaced with links to a phishing site, and a copy of the malicious QuickTime video is embedded into the user’s site. Any other users who visit this newly-infected profile may have their own profile infected as well.

An infected profile can be identified by the presence of an empty QuickTime video or modified links in the MySpace header section, or both.

For more on this and screen shots head over to Websense.

Article Link

Tags: , , ,

Tag It:
  • Digg
  • del.icio.us
  • Slashdot
  • Technorati
  • SphereIt
  • StumbleUpon
  • Fark
  • YahooMyWeb
  • Furl
  • Spurl
  • Ma.gnolia
  • NewsVine
Related Articles:

  • Apple Fixes Serious QuickTime Bug
  • Your December 12th Morning Starchucks Grande
  • Google’s Orkut Hit By Data-Stealing Worm
  • Apple QuickTime Exploit In The Wild
  • Swarm of QuickTime Bugs Found
  • MySpace XSS QuickTime Worm of Myspace Html Codes Blog said,

    December 2, 2006 @ 9:30 am

    [...] Original post by Dave for Myspace News MySpace XSS QuickTime Worm [...]

    RSS feed for comments on this post · TrackBack URI

    Leave a Comment