Thursday November 20, 2008 7:17 PM AEST
Latest Comments
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM
 
"I actually love the RoboForm software myself. I use it all of the time and it takes all of the ..."
by Omarra Byrd | Nov 18, 2008 8:19 AM
Web

Month of MySpace bugs kicks off

  • Email a Friend
  • Print Page
Month of MySpace bugs kicks off
By Dan Kaplan
Apr 3, 2007 9:54 AM
Tags: Month | of | MySpace | bugs | kicks | off
The pair, known only as Mondo Armando and Mustachio, said on their LiveJournal site Saturday that they plan to notify MySpace of each bug prior to publication, but they were not hopeful security officials would respond.

"We are not working with MySpace, although we would be happy to," the hackers said, adding they are using the month to highlight the dangers of sites similar to MySpace that have "users of various levels of sophistication."

Over the next few weeks, the hackers said they plan to reveal a variety of bugs, including flaws for cross-site scripting (XSS) attacks or ones that permit unauthorised access to user profiles.

The pair kicked off the initiative with a well-known vulnerability that speaks to very nature of MySpace. Users can edit their profiles using cascading style sheet (CSS) language and customise their profile URLs.

That means hackers conceivably can create the profiles to resemble the MySpace login page and use a legitimate-sounding URL to trick users into giving up their credentials.

"It’s a pretty light one, seeing how today is Sunday, and we don’t really expect the crazy MySpace Security Squad to actually do a lot of code changes on Sunday," the hackers said sarcastically.

Today the pair disclosed a vulnerability on the "cms.goto" application of "profile.myspace.com." that is caused by a lack of input validation and can lead to an XSS attack.

A MySpace spokesperson could not immediately be reached for comment.

Jeremiah Grossman, CTO of WhiteHat Security, told SCMagazine.com that the project underscores the vulnerability of most sites on the web. However, hackers are more likely to target MySpace flaws because the site has more than 130 million members.

"It's just a popular target," he said. "Nothing's necessarily more susceptible about it."

The undertaking is interesting because it focuses on a particular site, not a product or a system component as similar month-long projects have done, Grossman said.

"The popular websites out there are going to have to deal with disclosure just like the Microsoft and Oracles of the world," he said.

MySpace is no stranger to malicious users. In December, the site – the fifth most trafficked web destination, according to Alexa – hosted a patch for Apple after MySpace was hit by a cross-site scripting worm, which took advantage of JavaScript functionality in the QuickTime player used by many users to run videos on their profile pages.

The goal of the attack was to steal login credentials and lure users to a pornographic site hosting spyware.

And over the summer, the site suffered from flawed banner ads that hosted the Windows metafile vulnerability, permitting drive-by downloads.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers