This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

New MySpace link hack in use

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.websense.com/securitylabs/blog/….php?BlogID=173
Feb 21 2008 - "Websense Security Labs has been tracking a technique that allows for easier social engineering on MySpace. The technique allows the creation of malformed anchor tags with style attributes that cover most of the clickable page with whatever link an attacker wants… The malformed anchor tags seem to be getting past MySpace's parsing, which usually converts links to their own redirect format off of their msplinks.com domain… This technique makes it easier for malicious users to steer profile visitors to an external Web site. An unsuspecting user might try to click on what would normally be safe links hosted on MySpace, such as the "View My: Pics" link on every profile… because of this hack, users are actually taken to an external site… We have detected a music profile with over 12 million page views and over 435K friends using this hack to link to a site that redirects you several times until you finally arrive at a MySpace phishing site. The first redirect is a JavaScript redirect with a basic message on the page, and it redirects to "thanks.php" on the same domain. The second redirect is a 302 with the page being hosted on a different domain that has been created to look like a MySpace URL… The profile also uses viral marketing techniques to encourage fans to copy and paste a snippet of code into their profiles. This should give users updates on the band, but in fact this code snippet is just spreading the same link to the MySpace phishing site. We have monitored this profile and noticed that the link to the phishing site has been updated, presumably because the phishing site has been shut down."

(Screenshots available at the URL above.)

:ph34r:
More on this…

- http://preview.tinyurl.com/327zaj
February 20, 2008 (Symantec Security Response Weblog) - "…Symantec has recently observed millions of user profiles of a certain social networking site carrying malicious links. The interesting thing here is that the malicious link appears to be a comment from a trusted friend. In most cases the trusted friend is not the perpetrator behind these attacks. The most likely scenario is that the trusted friend’s social networking site credentials have been compromised and used by the phishers to post malicious comments to everyone in the compromised contact list… With some more research we discovered more than five million user profiles carrying these malicious links… Another interesting thing to note here is the anatomy of the link. The phishers registered a domain similar to the legitimate link that would have been used on that social networking site, except that they replaced slashes with dots. This could fool even the savviest user, because the links look “almost” legitimate. It turns out that just plain old phishing wasn’t good enough for the phishers and they decided to add a few exploits to the mix. So, upon visiting the site not only does the user get phished, but also served a variety of exploits. The exploits are obfuscated and exploit the following vulnerabilities:
• MS06-14 (MDAC Create Object)
• BID 21060 (WinZip FileViewCtrl)
• BID 19030 (WebViewFolderIcon)
• BID 21829 (Apple QuickTime RTSP) …"

(Screenshots available at the URL above.)

:ph34r: :ph34r: