TeamDroid
Google
 
Web TeamDroid
Myspace Worm Using Quicktime HREF Track
Posted on 12.06.06 by John @ 4:53 am

Apple Quicktime

Just great. For a long time I have been trying to figure out a way not to let Quicktime spawn web pages. Not only is it annoying but now it can get you phissed: 

It begins with a QuickTime file being embedded in a Profile page. If the user “runs” the file (simply visiting the infected page is enough to trigger the attack in most cases), it uses the HREF function to activate some JavaScript.

Allowing JavaScript from a movie file….whoops.

When this happens, the profile page is “infected” and pastes a fake overlay of options onto the profile page - the most serious of which is (of course) the fake login button. If your page has been affected, you will see a strange, blue navigation bar such as this on your page. If this is the case, you will need to clean out your profile and check if any of your friends have also been infected - if they are, you will continue to be reinfected…most likely via the friends list itself. We have seen reports of users complaining that even when they’ve removed the fake navigation bar from their page, it comes right back if one of their friends is infected - so it looks like the friends list is being exploited in much the same way the Orkut worm used a similar feature to spread. Except in this case, the only option to fix the problem is get your friend to remove the infection code from their page, or remove your friend from your list indefinitely.

Going back to the fake login, if you enter your details, you have officially been Phished.

Myspace Worm Using Quicktime HREF Track


Filed under: Apple and Computers and Dumb and News and To be used for Evil
Comments:

Trackback URL for this post

Leave a Reply


TigerDirect
Pinhole Photo Gallery Challenge


Main Menu
Home
Apple
Artistic
Computers
Cool
Design
DIY
Dumb
General
Hacked
Historic
Japan
Mad Science
Mods
News
Paper
Paranormal
Photography
Rants
Robots
Science
Space
Technology
Thailand
To be used for Evil
Uncategorized

Search

Send me a suggestion

The Sponsors


Pages

Links and Things

Credits and Copyright
Proudly powered by WordPress.
All content © TeamDroid
unless otherwise noted
Theme by Theron Parlin



Archives
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
December 2005
November 2005
October 2005
September 2005
August 2005
July 2005
June 2005
May 2005
April 2005
March 2005
February 2005
January 2005
December 2004
November 2004
October 2004
September 2004

Recent Entries
Steampunk, is it Design or just Bad Taste?
Now You're Cooking With ... USB?
Bankquest: Fight your way to riches
Sneaky Uses For Everyday Things
Mini Bear Mecha
Amazing Full Sized Iron Votom - スコープドッグ ブルーティッシュカスタム
Ants Threaten NASA
The Repeater
How to Hack Humans, Epilepsy Sufferers Targeted
Virgle: The Adventure of Many Lifetimes
New! Gmail Custom Time
$25 Head-Mounted Display
'Scarab' the Robot Goes to the Moon
BattleBots on ESPN in '08?
Solar-thermal plant In Arizona

Good Stuff
Technology Blogs - Blog Top Sites
Google PageRank 
Checker - Page Rank Calculator Blog Flux Directory
www.flickr.com
JohnKit's photos More of JohnKit's photos