MySpace
The phishing worm that hit MySpace may leave other sites vulnerable

QuickTime flaw could go beyond MySpace

Security firm warns that other sites could be infected

Written by Shaun Nichols in California

The QuickTime security hole that enabled a phishing worm to attack users of social networking site MySpace is leaving more users and websites vulnerable than was first thought.

Security firm F-Secure said that the vulnerability has been confirmed to exist in Mac versions of QuickTime, as well as the QuickTime Alternative codec package.

"Any malicious JavaScript code exploiting [the vulnerability] would affect the users of both operating systems," said F-Secure researcher S G Masood.

Apple, which makes and distributes QuickTime, distributed the fix to MySpace which then offered the patch to users who accessed the site with Internet Explorer and a detectible version of QuickTime.

But this move leaves millions of users unprotected, according to F-Secure. Other browsers, including Firefox and Safari, remain exposed, and all sites that allow users to upload QuickTime movies will be vulnerable to the same sort of worm that plagued MySpace.

"With no fix available, the only feasible workaround for these social networking sites, and other websites on the internet, is to completely block users from uploading Apple QuickTime content," said F-Secure.

The QuickTime vulnerability first gained attention early this month when a worm known as QuickSpace began spreading on MySpace.

The worm spreads itself through the profile pages of MySpace users, altering the profiles of anyone who views the infected page and redirecting them to a MySpace phishing site.

This malicious site then uses stolen passwords to propagate spam messages with links to adware-installing sites.

Tags:

Further reading

Related articles

vnunet.com analysis: Browser wars changing security game

Variety and competition bring new protections and new threats   More...

Mac Trojan attack gathers steam

OS X attack being served up with PC malware   More...

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Phishing Trojan targets Mac OS X

Fake codec delivers Mac malware   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

18 Jul 2008

7.91 MBPodcast Special: Views from the Valley More...

17 Jul 2008

3.61 MBMalware explosion, nanotech fears and a jailed spammer More...

16 Jul 2008

4.17 MBiPhone 3G hacked, YouTube privacy deal and BT ad complaints More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement