MySpace Bug Hunt Gets Off to a Slow Start
Hackers kick off their month of exposing MySpace vulnerabilities with a softball.
Jeremy Kirk, IDG News Service
A group of hackers has kicked off its month of MySpace vulnerabilities, which it hopes will make more of a splash than January's month of bugs for Apple Inc.'s software.
But they acknowledge they've started off with a softball, as the first one revealed on Sunday isn't too dangerous, they wrote.
The problem involves URL (Uniform Resource Locator) spoofing. An attacker could build an official-looking MySpace page using MySpace's CSS (Cascading Style Sheets) editing features that's designed to solicit a person's log-in details. The fake page could have a URL that reads "www.myspace.com/PasswordReset."
The problem is credited to mybeNi websecurity.
"Note, it's a pretty light one, seeing how today is Sunday, and we don't really expect the crack MySpace Security Squad to actually do a lot of code changes on Sunday," they wrote. "So, we went with one they probably don't care about, and isn't terribly dangerous on its own."
The hackers, who go by the names Mondo Armando and Müstaschio, have said they picked MySpace for their project for its high number of users. MySpace had 64.4 million unique visitors in February, according to comScore Networks, which tracks Web site traffic.
The hackers have informed MySpace of the project, they said.
"They are adhering to the company line that they do not respond to inquiries regarding security," one of the hackers wrote in an e-mail to IDG News Service.
The "month of bugs" theme has been criticized as gimmicky and, sometimes, just not that exciting. Others have done the "Month of kernel bugs" and "Month of PHP bugs" projects. The month of Apple bugs, which ran throughout January, turned up flaws but nothing too alarming.
But MySpace might prove more fertile. It has frequently been targeted by hackers since a single compromised account can open a door to potentially hundreds of thousands of other users, which can be targeted with spam or infected with malicious code.
In December, a worm rapidly spread across user profiles using a cross-site scripting weakness and a feature within Apple's QuickTime multimedia player.
Users who visited another MySpace profile could be infected by viewing an embedded QuickTime file, which could then begin an attack to capture the user's log-in details.
If the MySpace vulnerabilities aren't that thrilling, the hackers said it could aid the end of month-long bug-finding sprees.
"If it kills this Month of Whatever fad, then hurray for everyone, it's over," they wrote on their Web site.
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
A Guide to Business IT
Laptop Showcase
Related Software Articles
- Psystar Deserves a Chance to Compete Analysis: A little competition on its own turf might be good for Apple--and for customers.
- Microsoft Kills OneCare to Offer Freebie; So Long, Norton Bundling a security app with the operating system is good news for users and bad news for standalone security suites.
- Microsoft's New Xbox Experience Launches, Netflix Users Go Wild Today's the day your Xbox 360s get a total (and totally free) makeover, including fully integrated streaming Netflix video support.
- Can Two Security Suites Co-Exist? Bob Carne wants to use Trend Micro Internet Security as added spyware protection, along with Norton 360. They don't play well together.
- Review: Google Mobile App, Revisited Speak, and you shall find. Ask, and you shall receive. Let your voice ring out, and at least two times out of three, you will...
Best Prices on System Utilities
Windows Live OneCare 2.0 (Full Product)Price: $24.27
VMware Fusion (Full Product, Mac)Price: $59.99
Parallels Desktop (Full Product)Price: $20.00
Norton Partition Magic 8.0 Rev1RetailPrice: $17.99
Parallels Desktop 3.0 for MAC - BoxPrice: $49.95
Norton SystemWorks 11.0 (Full Product)Price: $20.99
- CDW Security Center Is your data protected? Visit the CDW Security Center Learn where you may be vulnerable and how to address those risks.
- Asus Laptop Showcase Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more...
- Personal Productivity Want to make the most of your limited time? Click here for more info...








"MySpace Bug Hunt Gets Off to a Slow Start" Comments