Follow Us

New type of hack hits MySpace

Alicia Keys unplugged.

A new type of hack has been used to hit MySpace sites, including singer Alicia Keys' page.

Keys' MySpace page and that of others were flagged by users of Exploit Prevention Labs' LinkScanner software, which blocks pages containing malicious code. The discovery came after users began reporting that Keys' page was blocked, according to Roger Thompson, chief technology officer of LinkScanner.com.

"When we saw it was MySpace and Alicia Keys, we took a good look at it," he said.

When a visitor views the page, an exploit first attempts to install malware on the visitor's computer if it is not properly patched. Thompson said he was not sure yet which flaw the malware was looking to exploit. If that is not successful, the user is then asked to install a fake codec to view a video. Thompson explains the process in this video.

If both of those should fail, the user is also vulnerable if he or she clicks anywhere on the page that is not a legitimate link - including the ads. "If your mouse slips a bit from what you meant to click, you get the background [link]," which references a site based in China, co8vd.cn, and also attempts to install malicious code. Thompson said he had not seen that kind of "image-background link" before.

The domain is registered to Xiamen Hua Shang Sheng Shi in China. The company could not immediately be contacted for comment.

Because the attack affected several different pages, including one of a high-profile figure like Keys, Thompson believes this is a hack of MySpace, and not a case of attackers simply uncovering the user names and passwords for those pages.

MySpace said it had already taken care of the problem.

"Individuals who try to phish our members are violating the law and are not welcome on MySpace. We have blocked and removed the source of this phishing attempt and restored the profile," a MySpace spokesperson said by email. Thompson confirmed that the Keys page was now clean, but added, "We'll see what happens over the next few days."






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *