Saturday | 5 July, 2008
ARN

Security

Hackers sneak tricks into MySpace band pages
Several band MySpace profiles have been rigged to serve up malicious software, according to security vendor FaceTime Communications.
Jeremy Kirk (IDG News Service) 01 November, 2007 05:38:21

Related Stories
  • +

    IPv6 Will matter to the enterprise in five years 10 November, 2007 08:30:12

    Routing guru Jeff Doyle says there's no need to move to IPv6 now, offers design tips for OSPF nets, discusses Layer 2 vs. Layer 3 routing and shares more advice with attendees of his live Network World chat.
    Welcome to Network World Chats. Our guest today is Jeff Doyle, celebrity author, Cisco Subnet blogger and networking guru. He has come prepared to answer your questions on all things routing.
  • +

    True crime: The botnet barons 04 January, 2008 07:03:57

    Two weeks ago, the feds revealed the names of eight people who had used botnets to engage in nefarious activity. Here are their stories
    When federal agents announced on November 29 that they'd indicted or convicted eight individuals accused of using botnets (networks of computers infected with Trojan horse applications) to engage in criminal activity, the press release barely explained the nature and extent of the men's crimes -- or the investigations that led to arrests in an operation the FBI and other law enforcement agencies have termed Bot Roast II.
  • +

    Five data leak nightmares 08 January, 2008 10:20:34

    When Home Depot lost a laptop containing personal information on 10000 employees, it was just the latest in a string of high-profile data-leak incidents.
    Data breaches cost companies an average of US$197 per record in 2007, according to a study by the Ponemon Institute. The average cost of a data breach was US$6.3 million, up from US$4.8 million in 2006.
ARN Directory | Distributors relevant to this article
Additional Resources
ARN Library

Newsletter Subscription

Sign up for our ARN newsletters!
The premier provider of daily news to the IT channel, covering business, technology, products, and services.
Delivered Monday, ARN Security is the only channel-specific weekly security service dedicated to the Australian IT channel.
RSS Feeds

Several band profiles on MySpace have been hacked to serve up some nasty tricks, according to security vendor FaceTime Communications.

The bands' MySpace pages have a transparent overlay that, when clicked, either links to a Web site that tries to start downloading malware disguised as a media codec or attempts to exploit a browser security flaw, said Chris Boyd, security research manager with FaceTime.

When a cursor passes over part of the overlay, the IP (Internet Protocol) address for a Web server in China is shown in some browsers. However, the fake media codec site is hosted in Russia, Boyd said. He posted screenshots of the problem on his blog Wednesday.

At some point, the log-in details for the bands' pages must have been obtained, likely through a phishing attack, Boyd said.

"So far, I think we've seen around seven or eight music bands hacked -- not a huge number as it seems to be pretty fresh," Boyd said.

But if the hackers have the bands' log-in details, they can send bulletins to users who have joined the site as friends. Those bulletins are used to attract more people into visiting the infected pages and potentially downloading the malware. That could ramp up infection levels, Boyd said.

"It's a great hook for a malware writer to tap into," Boyd said.

MySpace officials could not immediately be reached for comment. Boyd said the company has been notified by FaceTime via e-mail.

ARN Directory | Distributors relevant to this article
Market Place

ARN Member Login

 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news
Play
Channel Watch
  • Brian's bloopers

    It takes a long time to produce an episode of Channel Watch. Maybe you'll understand why after watching this...

Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

Australian water treatment company uses four GFI products to protect its network

OSMOFLO, an Australian company, implemented a suite of four GFI products to protect its network from viruses and spam, to monitor and control internet usage and to save time and money on faxing.

Sponsored Links