Saturday | 5 Jul 2008
PC world
Site Menu
Review Finder
PC World Business
Resource Centre

Broadband and Internet / Security & Safety

News

Hackers sneak tricks into MySpace band pages
Several band MySpace profiles have been rigged to serve up malicious software, according to security vendor FaceTime Communications.
Jeremy Kirk (IDG News Service) 01/11/2007 05:38:21

iPhone Centre
iPhone CentreFind out all about the iPhone at our iPhone Centre. News, reviews, how-tos and video - all in one location.
  • +

    Tomizone announces independent Wi-Fi for the iPhone 04/07/2008 14:10:00

    First independent iPhone Wi-Fi service
    Wi-Fi operator Tomizone yesterday announced an independent Australian Wi-Fi service for the Apple iPhone. The service is slated to begin on 11 July, the same day the iPhone 3G is released locally.
  • +

    The low-down on the iPhone 3G down-under 04/07/2008 08:55:58

    Australia will be among the first 22 countries alongside the US, UK, Germany and Japan, to receive the new iPhone from Friday, July 11.
  • +

    Expect iPhone scams, security firm says 04/07/2008 08:04:25

    Apple's launch of its new iPhone 3G will produce a flurry of spam and scams, a security company warned Thursday.
Zones
Zone logoZones provide focussed content from PC World and leading technology partners.

Several band profiles on MySpace have been hacked to serve up some nasty tricks, according to security vendor FaceTime Communications.

The bands' MySpace pages have a transparent overlay that, when clicked, either links to a Web site that tries to start downloading malware disguised as a media codec or attempts to exploit a browser security flaw, said Chris Boyd, security research manager with FaceTime.

When a cursor passes over part of the overlay, the IP (Internet Protocol) address for a Web server in China is shown in some browsers. However, the fake media codec site is hosted in Russia, Boyd said. He posted screenshots of the problem on his blog Wednesday.

At some point, the log-in details for the bands' pages must have been obtained, likely through a phishing attack, Boyd said.

"So far, I think we've seen around seven or eight music bands hacked -- not a huge number as it seems to be pretty fresh," Boyd said.

But if the hackers have the bands' log-in details, they can send bulletins to users who have joined the site as friends. Those bulletins are used to attract more people into visiting the infected pages and potentially downloading the malware. That could ramp up infection levels, Boyd said.

"It's a great hook for a malware writer to tap into," Boyd said.

MySpace officials could not immediately be reached for comment. Boyd said the company has been notified by FaceTime via e-mail.

More about FaceTime, VIA, HIS Limited

Market Place
Sponsored Links
close
Hot Deals
What’s New
Sponsored Links