AplusWebMaster
Topic Starter
FYI…
- http://www.websense.com/securitylabs/blog/….php?BlogID=173
Feb 21 2008 - "Websense Security Labs has been tracking a technique that allows for easier social engineering on MySpace. The technique allows the creation of malformed anchor tags with style attributes that cover most of the clickable page with whatever link an attacker wants… The malformed anchor tags seem to be getting past MySpace's parsing, which usually converts links to their own redirect format off of their msplinks.com domain… This technique makes it easier for malicious users to steer profile visitors to an external Web site. An unsuspecting user might try to click on what would normally be safe links hosted on MySpace, such as the "View My: Pics" link on every profile… because of this hack, users are actually taken to an external site… We have detected a music profile with over 12 million page views and over 435K friends using this hack to link to a site that redirects you several times until you finally arrive at a MySpace phishing site. The first redirect is a JavaScript redirect with a basic message on the page, and it redirects to "thanks.php" on the same domain. The second redirect is a 302 with the page being hosted on a different domain that has been created to look like a MySpace URL… The profile also uses viral marketing techniques to encourage fans to copy and paste a snippet of code into their profiles. This should give users updates on the band, but in fact this code snippet is just spreading the same link to the MySpace phishing site. We have monitored this profile and noticed that the link to the phishing site has been updated, presumably because the phishing site has been shut down."
(Screenshots available at the URL above.)

- http://www.websense.com/securitylabs/blog/….php?BlogID=173
Feb 21 2008 - "Websense Security Labs has been tracking a technique that allows for easier social engineering on MySpace. The technique allows the creation of malformed anchor tags with style attributes that cover most of the clickable page with whatever link an attacker wants… The malformed anchor tags seem to be getting past MySpace's parsing, which usually converts links to their own redirect format off of their msplinks.com domain… This technique makes it easier for malicious users to steer profile visitors to an external Web site. An unsuspecting user might try to click on what would normally be safe links hosted on MySpace, such as the "View My: Pics" link on every profile… because of this hack, users are actually taken to an external site… We have detected a music profile with over 12 million page views and over 435K friends using this hack to link to a site that redirects you several times until you finally arrive at a MySpace phishing site. The first redirect is a JavaScript redirect with a basic message on the page, and it redirects to "thanks.php" on the same domain. The second redirect is a 302 with the page being hosted on a different domain that has been created to look like a MySpace URL… The profile also uses viral marketing techniques to encourage fans to copy and paste a snippet of code into their profiles. This should give users updates on the band, but in fact this code snippet is just spreading the same link to the MySpace phishing site. We have monitored this profile and noticed that the link to the phishing site has been updated, presumably because the phishing site has been shut down."
(Screenshots available at the URL above.)