Oct 27, 2006 : MySpace Attacked By Hackers
📅 - Hackers have compromised social networking Web site MySpace (myspace.com) by presenting a spoof login form on the main site, Web analytics firm Netcraft (netcraft.com) discovered on Thursday. The modified login form, created on MySpace's own Web site, is designed to submit the victim's username and password to a remote server hosted in France.
Netcraft has notified MySpace of the vulnerability, but the login form still remains active. Since the fake login page is hosted on MySpace's own servers and fails to show any signs of external content, such as cross-site scripting or open redirects, it appears authentic. As a result, even security-conscious users can potentially fall victim to the attack.
The attack is launched from a profile page, where the username is login_home_index_html, and employs custom-coded HTML to hide the real MySpace content from the page, displaying its own login form instead. Once a user account has been compromised, personal data can be stored.
A member of the Netcraft Toolbar community alerted Netcraft of the attack, and Netcraft promptly blocked it after investigation. Netcraft Toolbar users can protect themselves against this phishing attack, and will be warned when visiting the fraudulent login form or when accessing the data-harvesting server in France.
Netcraft has notified MySpace of the vulnerability, but the login form still remains active. Since the fake login page is hosted on MySpace's own servers and fails to show any signs of external content, such as cross-site scripting or open redirects, it appears authentic. As a result, even security-conscious users can potentially fall victim to the attack.
The attack is launched from a profile page, where the username is login_home_index_html, and employs custom-coded HTML to hide the real MySpace content from the page, displaying its own login form instead. Once a user account has been compromised, personal data can be stored.
A member of the Netcraft Toolbar community alerted Netcraft of the attack, and Netcraft promptly blocked it after investigation. Netcraft Toolbar users can protect themselves against this phishing attack, and will be warned when visiting the fraudulent login form or when accessing the data-harvesting server in France.
Reads: 1881 | Category: General | Source: TheWHIR : Web Host Industry Reviews
URL source: http://www.thewhir.com/marketwatch/102706_MySpace_Attacked_By_Hackers.cfm
Want to add a website news or press release ? Just do it, it's free! Use add web hosting news!