MySpace hacked, exploits target Alicia Keys' page and others
By Thomas Claburn
9 November 2007 12:47PM
Avoid Alicia Keys' Web page on MySpace. It's been hacked..
Roger Thompson, CTO at Exploit Prevention Labs, has found multiple hacked MySpace pages, including the page for Alicia Keys, the social networking site's fourth most popular music artist.
In keeping with what appears to be a new trend among security researchers, Thompson has released a video depicting the hack on YouTube. He has also posted details on his blog.
Visiting the page exposes the visitor to an exploit that installs malware unless the user is fully patched against the most recent security vulnerabilities. "They're using an exploit to install software in the background," Thompson explains in the video.
Even those with patched systems are vulnerable. The hackers have found a way to associate their malicious URL with what would normally be a non-clickable background area on the Web page. The result is that clicks outside specific clickable controls get captured and interpreted as a click on the malicious URL.
"If you click anywhere outside a given control, [the malicious URL] will be the default control that it goes to," Thompson explains. "It's a really interesting technique and it's going to catch a lot of people."
"What's not clear at this point is how they're doing it, and how widespread it is," Thompson says on his blog. "Neither Google nor MySpace seems to be indexing the critical bit of HTML. If you search for the exploit site (co8vd.cn), the only results seem to be victims, or people talking about victims."
In a conversation via instant message, Thompson said that social networking sites are increasingly become vectors of attack. "The whole point of browser stuff is that it bypasses the firewall," he explained.
A spokesperson for MySpace was not immediately available to comment on the attack.
Source : itnews.com.au
Saturday, November 10, 2007
MySpace hacked, exploits target Alicia Keys' page and others
Posted by ILL_Natured_gr at Saturday, November 10, 2007 0 comments
Labels: PC News, PC Security, Social Networks
Friday, September 14, 2007
Ad-based Trojan hits MySpace, Bebo and others
Ad-based Trojan hits MySpace, Bebo and others
Malware hidden in adverts
Matt Chapman, vnunet.com 11 Sep 2007
Users of high profile sites including MySpace, The Sun, Bebo and PhotoBucket have been exposed to a Trojan hidden within adverts.
The sites all ran advertising in recent weeks from the Right Media online ad exchange which were unknowingly infected with the Downloader.VBS.Agent.n Trojan.
"This is another example of how legitimate 'trusted' websites can unknowingly host malware," said Dan Nadir, vice president of product strategy at ScanSafe.
"Online ads have become a primary target for malware authors because they offer a stealthy way to distribute malware to a wide audience."
Nadir explained that the malware was particularly dangerous because it required no user interaction for infection to take place.
ScanSafe estimates that up to 12 million ads may have been delivered, exposing a large number of users to the Trojan.
The security vendor saw a surge in blocks of the Trojan beginning on 8 August and continuing until early September.
Nadir added that it will be very difficult to track down the source of the malware because the hacker used the distributed nature of online advertising to spread the code to hundreds of sites.
One of the infected adverts used a Flash file to generate an invisible iFrame. This was linked to an IP address containing obfuscated visual basic script that used the well-known MDAC exploit to download a Trojan executable.
ScanSafe believes that the malicious script inside the Flash ad avoided detection by Right Media because of the clever use of a referrer check. This meant that the advert only became active when delivered by a particular ad server.
The Downloader.VBS.Agent.n malware downloads other programs which are launched on the victim's machine without knowledge or consent.
ScanSafe said that several well known sites, including TomsHardware, have unwittingly hosted malware that was inserted via infected online ads.
Source : pcmag.co.uk
Posted by ILL_Natured_gr at Friday, September 14, 2007 0 comments
Labels: Internet, PC News, PC Security, Social Networks
