Hackers promise month of MySpace bugs

Two anonymous hackers are promising to publish MySpace.com bugs throughout the month of April

They won't divulge their real names, they call their project a "whiny, attention-seeking ploy," and they appear to take their fashion cues from Beastie Boys music videos.

But two hackers going by the names of Mondo Armando and Mustaschio promise to begin disclosing security vulnerabilities in MySpace, News Corp.'s popular social networking site, every day next month.

"The purpose of the exercise is not so much to expose MySpace as a hive of spam and villainy (since everyone knows that already), but to highlight the monoculture-style danger of extremely popular websites," wrote Mondo Armando in an e-mail interview.

"We could have just as easily gone after Google or Yahoo or MSN or IDG or whatever. MySpace is just more fun, and is becoming notoriously [obnoxious] about responding to security issues," he said.

These "Month of Bugs" projects have become a way for hackers to bring attention to both themselves and to security problems in certain types of products. Well-known hacker HD Moore kicked off the craze last year when he published one browser bug per day for the month of July. His effort was followed by a "Month of kernel bugs," a "Month of Apple Bugs," and a "Month of PHP Bugs."

The MySpace hackers launched their project late Thursday expressing simultaneous enthusiasm and disdain for the task ahead. "If it ends up being just as lame as the Month of Apple Bugs, then we haven't really missed the mark. If it's funnier, then great," they wrote on their project's blog. "If it kills this Month of Whatever fad, then hurray for everyone, it's over."

They intend to primarily publish cross site scripting bugs, which can allow an attacker to execute malicious script within a victim's browser, but they may also publish bugs that affect browsers or technologies like Flash or QuickTime.

Though the project, which launches on April 1, has all the appearance of a practical joke one well-known hacker said he'd been contacted by the Month of MySpace team with legitimate security questions. "Those guys and I have been keeping in touch," said Robert Hansen, chief executive of Sectheory.com. "It's funny but it's not a joke."

Whatever comes of the MySpace bug month, security experts are paying more attention lately to vulnerabilities in Web sites that allow users to upload their own content.

Last December a fast-spreading worm hit MySpace, flooding users with spam and copying a malicious QuickTime file all over the MySpace network.

If these attacks continue, MySpace will have a tough time balancing security with its desire to provide interactive tools that users love, said Ken Dunham, director of VeriSign's Rapid Response Team. "From a design perspective, it's difficult to wrap your arms around it," he said. "Even when they have countermeasures in place... it's trivial to obfuscate to evade their detection mechanisms."

News Corp. did not respond to requests for comment on the "Month of MySpace bugs."

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Robert McMillan

IDG News Service
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?