Alicia Keys hit by MySpace Trojan hack
This story was updated on Saturday, 10th November 2007 00:21 GMT to report additional details.
Multiple MySpace pages have been hacked in a bid to spread malware.
Targeted pages, including the site of R&B star Alicia Keys, have been loaded with links to Trojan horse malware that poses as a fake codec. As well as attempting to load the malware through a browser exploit the booby-trapped sites also attempt to trick users into downloading the fake codec.
Instead of using an iFrame injection method the poisoned profile uses an image map, so users clicking on anything over an area of a contaminated profile close to a pukka link will be taken to a maliciously-constructed website, hosted in China. The attack was discovered by Roger Thompson of Exploit Prevention Labs, who's posted an explanation of the attack along with a video here.
The discovery comes more than a week after researcher Chris Boyd published this post found similar shenanigans on myspace pages. The pages, Boyd found, had transparent overlays that linked to websites that tried to install malware, either by tricking a user into installing faux media codecs or by attempting to exploit vulnerable browsers. Thompson issued an apology to Boyd. "I didn't steal any of your work, and didn't mean to steal your thunder," he wrote.
As Thompson notes the beauty of the attack is that MySpace pages are such a pig's breakfast of clutter and multimedia files that would-be victims won't be surprised about having to load a codec and therefore all the more likely to fall for the ploy. It's unclear how many pages have been infected.
MySpace has increasingly become the subject of security concerns. In October 2005, a bug in MySpace's site design was misused to create a self-propagating cross-site scripting worm. More recently MySpace pages have been used to spread spyware, a trend continued in a more sophisticated form with the latest fake codecs attack. ®
More info about the exploit
Here is information about the software that installed through the security hole:
Why on earth would anyone WANT to visit MySpace anyway.
If you lie down with dogs...you get up with fleas...
Grammar checkers could be handy too... "It's unclear how many page have being affected" is, shall I say, an interesting way of putting it. :)
I know we're creeping into Slashdot pedantry territory, but I think it's fair enough to pick apart such issues in the articles themselves rather than the reply posts. It is a slippery slope, however ... after all smart-arse posts like these are just crying out to be picked apart by other readers ...