espn techguide home tvs homeaudio digitalcameras handhelds cellphones mp3players

Search:
Go!


MySpace to Apple: Fix that worm

After worm spreads on social-networking site, MySpace asks Apple to update its QuickTime media player.
By Joris Evers
Staff Writer, CNET News.com
Published: December 5, 2006, 12:54 PM PST

Story Tools

TalkBackE-mailPrint del.icio.us Digg this

MySpace.com wants Apple Computer to update its QuickTime media player software so it can't be used in attacks on the social-networking site.

The request comes after a worm in the form of a rigged QuickTime movie crawled onto MySpace.com over the weekend, changing people's MySpace profiles. The worm spread because of QuickTime's support for JavaScript code, experts have said.

"When we learned about an issue that exploits a feature in QuickTime and unfortunately targets MySpace users, we immediately contacted Apple to engineer a fix," Hemanshu Nigam, chief security officer at MySpace, said in an e-mail statement Tuesday.

When viewed by a MySpace user in Internet Explorer or Firefox, the specially crafted QuickTime video added itself to the user's MySpace page and replaced the links on the user's profile with links to phishing Web sites. The malicious software, dubbed Quickspace by F-Secure, infected a large, but unspecified number of MySpace users, according to the Finnish security company.

Apple is working on a QuickTime fix, but has a temporary solution available Tuesday, company spokeswoman Lynn Fox said in an e-mail.

"Recently we learned about an issue that exploits a feature in QuickTime used to target MySpace users. We have devised a way to disable this QuickTime feature for those who use Internet Explorer. We are working on a broader solution for all other users as well," Fox said in the e-mail.

Apple said it has provided MySpace with the temporary fix. The computer company said it would be up to the social-networking site to offer it to users. MySpace has not responded to an inquiry from CNET News.com as to when the temporary solution would be available to users.

While waiting for Apple to release a final fix, MySpace has blocked the Web links that attempt to exploit the issue and is scrubbing them from profiles on the MySpace site, Nigam said. MySpace has also reported the incident to law enforcement, he said.

MySpace, owned by News Corp., is a popular social-networking site estimated to have more than 70 million registered users. The worm exploits MySpace functionality along with a feature called HREF track in QuickTime that has legitimate uses but can also be abused, experts have said.

"This particular attack is not working anymore because of filtering of URLs," said Mikko Hypponen, chief research officer at F-Secure. "But the actual vulnerability still exists in the system. The final fix needs people to update their personal QuickTime player."

The object of the Quickspace attack apparently was to get people to visit the fraudulent Web sites crafted to look like MySpace log-in pages. It is unclear what the miscreants would do with the log-in data. But it could be used, for example, to exploit the user's profiles for advertising.

 88 comments
Post a comment

TalkBack

me to

morena2724 
Apr 8, 2007, 8:33 AM PDT

cant stay on my myspace profile

amagg22 
Mar 29, 2007, 1:57 AM PDT

help....

brandicj 
Feb 28, 2007, 7:45 AM PST

Help me to fix myspace

sachaelxox 
Feb 25, 2007, 1:35 AM PST

Unblock my Myspace Outgoing Mail

niki333 
Feb 13, 2007, 10:54 PM PST

New Profile On Myspace

juicy2C 
Feb 6, 2007, 10:00 AM PST

I can' log on either

juicy2C 
Feb 5, 2007, 5:59 PM PST

myspace

travieza619 
Feb 5, 2007, 4:39 PM PST

myspace

travieza619 
Feb 5, 2007, 4:38 PM PST

i cant loggin on myspace

x3tlsmith 
Feb 4, 2007, 5:13 PM PST

I can't even get on myspace,don't know why??

joann1965 
Feb 4, 2007, 12:23 PM PST

myspace aint up in moreno valley, ca

sneackers 
Feb 4, 2007, 11:06 AM PST

MySpace

debandwalt 
Feb 4, 2007, 9:29 AM PST

Fix that problem

robinduhe 
Jan 8, 2007, 8:01 AM PST

Fix that problem

robinduhe 
Jan 8, 2007, 8:01 AM PST

well it got me

missy&kadie 
Jan 6, 2007, 10:46 PM PST

Ha I dont get this

kaorichan2 
Dec 15, 2006, 8:37 PM PST

My account was hacked, they are of no help

jolietgeorge 
Dec 13, 2006, 10:38 PM PST

I warned them weeks ago

drew30319 
Dec 11, 2006, 9:26 PM PST

Myspace is lame

jcastanza 
Dec 8, 2006, 2:49 PM PST

That's just Nutty...

TigerG 
Dec 6, 2006, 6:07 PM PST

Patched ...

MacHeads 
Dec 6, 2006, 1:58 PM PST

Quicktime vs. Windows Media Player

sandsunsurf 
Dec 5, 2006, 11:24 PM PST

lies

nodeseven 
Dec 5, 2006, 8:26 PM PST

advertisement
Images: Adobe Photoshop Express finally arrives Featured gallery

Images: Adobe Photoshop Express finally arrives

New Web-based application for editing, organizing, and sharing images is free, and an account includes 2GB of storage.
View this gallery.

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

Markets

Market news, charts, SEC filings, and more

Related quotes

Apple, Inc. 187.62 -2.11 (-1.11%)
News Corporation CL B 19.99 0.13 (0.65%)
S&P 500 1,425.35 1.78 (0.13%)
NASDAQ 2,528.85 -4.88 (-0.19%)
CNET TECH 1,783.62 0.88 (0.05%)
  Symbol Lookup
Detroit auto show
Detroit auto show

Detroit auto show
Click Here

advertisement
Click Here


Copyright ©2008 CNET Networks, Inc. All rights reserved. Privacy policy|Terms of use