Free Newsletters

   All InfoWorld Newsletters
Security Adviser | Roger A. Grimes » More information on MySpace exploit

November 11, 2006 | Comments: (0)

More information on MySpace exploit

In my previous blog entry I talked about the password exploit outcome of a recent MySpace phish attack. I neglected to mention links to related newstories.

Netcraft Link

Sandi MVP blog

The latest hacks are only one in an increasing series of related malicious hacks.

What's worse is that there doesn't appear to be an easy, quick fix to the hacking that's going on. MySpace allows regular end users to modify their home pages with HTML. That right leads to a lot of power and is difficult to secure appropriately against maliciousness while allowing legitimate things to run. I'm not a big MySpace user, but my advice to anyone is to avoid MySpace until they get their security act together.

My initial gut feeling is that, like a lot of vendors, MySpace is handing out functionality faster than they are thinking about security.

11/26-06 Update:
Another link to the exploit
http://www.caughq.org/advisories/CAU-2006-0001.txt

Posted by Roger Grimes on November 11, 2006 04:59 PM


RATE THIS ARTICLE:





 

  •  
  • COMMENTS





Technology White Papers

 

InfoWorld Technology Marketplace

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
» BUY A LINK NOW

Sponsored Technology Links