MySpace Phishing Attack Leads Users to Zango Adware
An anonymous reader writes "Security site Spywareguide.com reports that a new worm is doing the rounds on MySpace. Taking advantage of the HREF feature in Quicktime movies, a fake login bar is displayed on infected users profiles via some JavaScript coding. If you login (via one of the many hacked servers hosting the JavaScript and movie file) you'll find you start spamming messages containing a pornographic movie. That movie leads to a site that's pushing Zango Adware left, right and center. Is this more evidence that Zango has yet to clean up their affiliate networks?"
I switched to FireFox, but it would be nice to be able to use Internet Explorer without Zango. I've tried several times to get rid of it with Ad-Aware. Anybody know how an easy way to get rid of it?
I remember the days when a movie file was... a movie file. What kind of idiot lets people access the web or, worse, run Javascript, from a bloody movie?
Please note that you can be infected by this virus by simply viewing an infected profile. It doesn't matter what browser you use, I was using Firefox 2.0 with AdBlockPlus and a decent filterset updater and was infected. I DO NOT believe it steals your password without going to the fake login page. So if your profile gets infected you are probably fine simply removing it
Here's how to remove it:
To truly protect yourself you need to adblock the offending Quicktime object - or better yet all
So, I just use VLC to play movies. It is free, allows full screen presentation, and there is no risk that if I click on the movie I will be sent into the bad old days of the web when an accidental click would bring up multiple windows, and the only way to stop them was to force the browser to quit.
Another piece of evidence proving that Apple is going the direction of monotizing customers rather than just building excellent product that people want to pay good money for.
"She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
Pardon my ignorance, but is this is a problem for Windows users only? Or Mac too? Linux? Or is javascript the problem (making any system vulnerable)?
Listen, in any affiliate program policing affiliates can be impossible. I think Zango's a disreputable and disgusting company, but that doesn't mean they're guilty in this case. Blame the affiliates.
Photos.
What idiot at Apple put a giant hole like this in?
An automatic URL loads as a movie is playing at the exact frame specified by a text descriptor timestamp in the HREF track. With automatic URLs, you can create a narrated tour of a website, use web pages as slides in a presentation, activate a JavaScript command, or do anything else that requires loading movies or web pages in a predetermined sequence.
That's got to come out of Quicktime players. They're a huge security hole now. That's just unacceptable.
Sounds like MySpace is the problem here.
To summarize, I think that the situation goes like this: A user places a movie file on their page manually to start with. People visiting that page view the movie which loads a link containing javascript. The javascript modified that MySpace user's profile to include the movie somehow.
Why do you even need a movie for this to happen? Why can javascript just change an entire MySpace page around? It sounds like the entire problem here is that MySpace users get too much customization abilities over their pages. A simple onload="infectuser()" javascript line would seem to me like it could accomplish the same worm effect.
Morphing Software
Yep. Leave it to Apple and their fast-and-loose programming to unleash another huge security hole. Now that something they make has hit something with mass market appeal (like MySpace), their "security through obscurity" strategy isn't going to protect them anymore.
How does one "clean up" an affiliate network? By nature, just like Amazon's spiffs program and Google's AdWords, anyone can sign up and use it. Obviously they should terminate this account, not pay the referral fees, blacklist the credit card number, and provide the signup/account logs to authorities when subpoenaed, but what else do you do? Manually police a billion ads a day?
I wouldn't be surprised if a fast adoption rate already triggered some kind of alarm bells at Zango to check it out more, but I don't think this is something that can be prevented. As with Gnutella, don't blame the application when people misuse it.
- Phishing attacks are becoming more common, and obviously, it is necessary for all users to be more cautious about exactly where they are entering their passwords -- this means being very alert to the contents of the URL bar (so as to not be deceived by things like "http://www.google.com.blahblah.phisher.tripod.co
m /google..."), and also not being misled by javascript window-within-window things that make something else look like the URL bar, etc. All this probably requires a greater level of attention than is within the capabilities of, say, old people (or even those teenagers on MySpace). So how do you make sure you don't give away your password to the wrong guys? - A common phishing-like attack is to somehow hack into some low-security site and get some username-password pairs, then try them at other sites. As you might guess, this trick is quite effective, because most people use the same password everywhere. Remembering hundreds of different hard-to-guess strings is somewhat hard, after all.
So given that Grandma is going to use the same password everywhere, and isn't going to be very alert to phishing, how do you still make it safe for her to use the internet? (Or, if you don't care about Grandma: How can you get away with remembering only one password and be reasonably safe against phishing?)There is a solution that's simple, effective, and comes at no cost -- no changes to the "user experience". It's PwdHash, developed by Dan Boneh and others at Stanford. It's available as a Firefox extension. Basically, to use it, you just pick for each site (while registering or changing the password) a password and prefix it with "@@". It could even be the same password for all sites. PwdHash will transparently convert the password you typed into a one-way hash based on the site's domain, so that the password with which you are registered on the site is actually something other than what you typed -- but you don't need to know what it is, because the next time you visit the site, you again type your password (begining with "@@"), and PwdHash will send the site your correct password (does the same thing again). So if a phisher (who is by definition on some other domain) tries to steal your password, he actually gets a different one from what the correct site would get. (Oh, and PwdHash warns you if you type "@@" into something that is not a password field.) Everything else works the same -- all you have to do is to consistently type "@@" before your password each time (or hit F2, alternatively). The idea of domain-based generators is not, new, but the beauty of this one is that it fits perfectly into one's existing workflow. A long as you ask Grandma to pick a password that "begins with" @@, you can be sure no phishing website will get her password. (Of course, it is still susceptible to email scams and malware programs, but at least safety while browsing is taken care of.)
The researchers demonstrate it as a solution to phishing, but I use it simply because remembering too many passwords is a pain. And it's by some of the top Crypto researchers, so you can be quite sure it doesn't have any stupid vulnerabilities. Read the paper (or see the Powerpoint presentation if you'd prefer it) for a more in-depth consideration of other issues. (Interestingly, one of the co-authors is Stanford student and Firefox guy Blake Ross.)
Firefox: NoScript. ;-)
Extra protection for your Firefox: NoScript allows JavaScript, Java and other executable content only for trusted domains of your choice, e.g. your home-banking web site. This whitelist based preemptive blocking approach prevents exploitation of security vulnerabilities (known and even unknown!) with no loss of functionality... Experts do agree: Firefox is really safer with NoScript
Is not the ability to customize, but the lack of confirmation, or a captcha. Because If you allowed to run movies trough flash,... that mean you allowed to run javascript. Running javascript as yourself mean other people can make ajax call, or whatever, to mimick yourself. Having captchas will stop that thing. But will make editing that profiles slighty slow, of course.
-Woof woof woof!
Fuck me, no, dearheart. This just proves that porn spammers love Zango so much that they distribute it without thought of pecuniary gain!
Zango are the filthiest scum outside of Al Quieda.
Sent from my ASR33 using ASCII
This exploit also infects .mp3 files and isn't just limited to .mov files unfortunately. If you thought a patch of just .mov files was going to solve it, you're wrong. This is a rather old exploit, there was a site that found it first I forget the name however.
.mov exploit for months, many of them just didn't make a worm out of them. That's old news in the myspace phishing scene to be honest. There's other ways to make worms, the .mov one is seriously old news. All these news entries are completely outdated.
Phishers have been using the
This phishing worm almost makes me want to install a Quicktime binary in wine....to bad there is no Linux variant with worm capabilities for Quicktime yet! Almost makes me wish I was using Windows. Then I could get more porn and not even have to ask. All those hot hot hot Quicktime automated babes and us poor Linux geeks just have to settle for manual sex!
Buy Steampunk Clothing Online!
And this makes me ponder why the fsck MySpace doesn't use SSL for their logins. Not that it necessarily helps against phishing if a convincing page is presented, but at least Firefox would politely make the address bar yellow and display the lock icon plus "login.myspace.com" (or whatever it is) in the status bar on the bottom-right corner of the browser.
The discussion is deliberately nontechnical, but I did a comparison of password generator utilities last year and pwdhash came out on top.
Just to be sure, has anyone checked to see if this is a joe-job? Shady competition in a shady area?
:-)
Maybe this is the way nature/evolution handles things when laws don't work? Hey, I'm just asking....
.f00Dave
YOU DO NOT TALK ABOUT ___!
Please, for the good of Humanity, vote Obama.
Zango, in and of itself, is crapware. Frankly, they shouldn't be in business at all, IMHO.
...but if you've got Windows Media Player, I can embed a script in Microsoft's .asx format and have WMP serve up whatever sort of mischief I can code up, cleverly hidden in an audio or video media file. Supposedly Microsoft has been paying attention to the issue, but just between you and me I wouldn't have your bank's login page open in IE while playing any unfamiliar .asx or .asf files:
http://support.microsoft.com/kb/828026
* * * * * *
Adobe Illustrator is a programmer's idea of how a graphic artist should work. CorelDraw is a graphic artist's idea of how a programmer should code.
How many stupid JavaScript problems do we need to have before NoScript comes standard with Firefox? Today's assignment is, write 100 times: JavaScript is an exploit vector!
A partial solution is actually pretty simple.
...
It's a bit of a headache to work out the logistics, but the banks simply should not allow logging in with a general purpose browser. All sorts of things can be done with a special purpose browser, from preventing any transmission from proceeding when either side provides the correct encrypted response, to using one-time pads,
And then I remember that, if there is spyware on the box, it's kind of hard to be sure that the one-time pad list, the encrypted response generator, and all the other fancy gadgets, are not being commanded by the adware instead of directly by the human.
But general purpose browsers (including the QuickTime browser) have just gotten too stuffed with functions.
Hi, I'm new to this forum. I do have an online site where I publish affiliate sites. Is there an online website that posts all of the affiliates that may be using unethical means to increase their business on the various publisher's websites? I'm attempting to keep my family oriented site "clean" of any spyware, etc. Check it out at http://continue.to/lasvegas Please let me know if there is a site that tracks unethical affiliates. Thank you. Ed Denaut, Owner of Denaut International ejdenaut@yahoo.com
at making up domain names.
Fango, bamzu, fandango, skype, and many more that don't spring immediately to mind I'm sure.
I realize every word and two-word combination in the english language is probably already taken by now, but give me a break. At least fork out the bucks to a squatter instead of making up ridiculous names.
This message brought to you courtesy of http://www.guwak.com/