This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Malicious Code: MySpace XSS QuickTime Worm

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.websense.com/securitylabs/alert…php?AlertID=708
December 01, 2006
"Websense® Security Labs™ has confirmed the existence of a worm spreading on the MySpace network. This worm is exploiting the Javascript support within Apple's embedded QuickTime player (1). This is used in conjunction with a MySpace vulnerability that was announced two weeks ago on the Full-Disclosure mailing list (2). The vulnerabilities are being used to replace the legitimate links on the user's MySpace profile with links to a phishing site.
Once a user's MySpace profile is infected (by viewing a malicious embedded QuickTime video), that profile is modified in two ways. The links in the user's page are replaced with links to a phishing site, and a copy of the malicious QuickTime video is embedded into the user's site. Any other users who visit this newly-infected profile may have their own profile infected as well.
An infected profile can be identified by the presence of an empty QuickTime video or modified links in the MySpace header section, or both.
1. http://www.gnucitizen.org/blog/backdooring-quicktime-movies/
2. http://seclists.org/fulldisclosure/2006/Nov/0275.html
3. http://www.apple.com/quicktime/tutorials/hreftracks.html …"

(Site screenshot available at the Websense URL above.)

:ph34r:
The phishing attempts also seem to lead users to Zango software installs, see PGs write up @ Greynet Blog

A while ago on the Spywareguide Blog, I covered a technique being used in Peer to Peer land involving URLs being embedded in Quicktime movies, which would then pop open a website. This has now been taken to the next level, with an intensive and seemingly never ending Phish attack, the sole aim of which seems to be directing end-users to a collection of Zango movies on a pornographic website. The Phish pages are hosted on compromised servers - presumably the people doing the hacking aren't particuarly brilliant at it, because they keep getting found out.

More…

- http://www.f-secure.com/weblog/archives/ar…6.html#00001038
December 2, 2006
"…Infected MySpace pages are easy to find. They've had their standard MySpace header replaced with a new one… The links here do not point to MySpace like they should. Instead they point to four different sites, hosting MySpace look-alike pages… When you visit an infected page with IE, an embedded MOV movie file (piAF2iuswo.mov) will be downloaded. The MOV file contains a Javascript snippet that will download a Javascript file (js.js) which will modify YOUR MySpace profile (if you have one). After that, everybody who visits your MySpace profile gets hit too.
The final target seems to be to steal MySpace logins in mass quantities. The infected files are hosted on several different sites…"

(Screenshots available at the URL above.)

Also see:
> http://www.f-secure.com/v-descs/js_quickspace_a.shtml

> http://www.symantec.com/enterprise/securit…-99&tabid=2

:ph34r:
FYI…

- http://blog.washingtonpost.com/securityfix…ps_adult_1.html
December 4, 2006
"…This scam is powered in part by an ill-conceived feature included in Apple's QuickTime video player software that allows embedded video files to load Web content from other sites… Even infected Myspace blogs whose authors have the poisoned QuickTime video and malicious links scrubbed from their pages can expect to get reinfected when other Myspace users on their "friends" lists get hit by the worm, says this alert* sent out by MySpace administrators. Victims should remove infected blogs from their "friends" lists until those MySpace users take action to clean up their own pages. Myspace users who notice odd changes to the MySpace site navigation bar, or unapproved messages being mass-spammed from their accounts, should consider their accounts stolen and change their passwords…"

* http://forum.myspace.com/index.cfm?fuseact…&IsSticky=0
December 1, 2006
"…Your profile first becomes infected with the worm if you go to another profile that has it. What you have to do is, edit your profile, and remove any codes you didn't put there yourself.
If you find that the worm keeps coming back, it means you have been onto someone else's profile that is still infected. If you are using FireFox, there is a good chance you won't get the worm, because of Adblock. If you don't have Adblock, you can get it here**. ADBLOCK ONLY WORKS ON FIREFOX, SEAMONKEY AND THUNDERBIRD. Once you download Adblock, open FireFox and click on Tools (which should be next to Bookmarks up the top). Then click on Adblock Plus. In the box where it says New Filter, type in this:
*.mov …Then click Add Filter, and OK. This should protect you from getting the worm if you use FireFox. You can now go onto anyone's profile without getting infected. HOWEVER, if you don't use FireFox, it might be a good time to start. Your profile will keep getting infected if you use Internet Explorer, no matter how many times you delete the code…"
** https://addons.mozilla.org/firefox/1865/

:ph34r: