MySpace
Security companies have already found vulnerabilities in MySpace

Month-of-bugs project targets MySpace

Tongue-in-cheek campaign finds flaws in social networking site

Written by Shaun Nichols in California

Advertisement

Social networking site MySpace has become the latest company targeted by a 'month of bugs' project. 

The project, run by security researchers using the aliases 'Mondo Armando' and 'Müstachio', is officially known as Month of MySpace Bugs, Yuss!, or Momby for short. 

Previous 'month of bugs' projects have targeted everything from Mac OS X to PHP

As the name suggests, the projects aim to disclose a new vulnerability every day for a month. This latest effort, however, takes as many swipes at other month of bugs projects as the target itself.

"Months of Bugs are annoying, so rather than suffering through another, we figured it'd be better to just create our own where we could at least direct the content a little," said 'Mondo Armando' in the 'official announcement' of the project.

The pair decided on targeting MySpace for a variety or reasons, including its substantial user base.

"Months of Bugs are whiny, attention-seeking ploys for acceptance. MySpace's design use is to enable whiny, attention-seeking ploys for acceptance," said the researchers.

The project will take place during April and will be run from a special LiveJournal blog, or at an alternative site should the account be revoked by LiveJournal owner Six Apart.

"Most of what we intend to publish are silly XSS/misleading CSS style bugs that MySpace users may actually be able to use for a little while, and that involve only MySpace.com stuff," wrote Armando.

The pair are also asking fellow researchers to contribute their own bugs to Momby, requesting details and working proof-of-concept samples.

'Mondo Armando' and 'Müstachio' may not need to search too hard for content in the first few days. F-Secure and Sunbelt Software alerted users on Monday to a pair of security hazards currently doing the rounds on MySpace. 

One bug, according to F-Secure, uses a QuickTime vulnerability to steal user information. The other uses fake MySpace profile pages to trick users into downloading adware programs disguised as video plug-ins, according to Sunbelt.

Tags:

Related whitepapers

Related jobs

Do you agree?

Most commented stories

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

05 Sep 2008

8.64 MBPodcast Special: Views from the Valley More...

Podcast image

04 Sep 2008

12.7 MBComputing podcast 4 September 2008 More...

Podcast logo

02 Sep 2008

8.39 MBEco-Entrepreneur Podcast: Bulldog More...

Poll

INTERNET EXPLORER 8

INTERNET EXPLORER 8

Are you intending to download Internet Explorer 8 when it becomes available?

Previous poll results

Spotlight

LogMeIn Rescue+Mobile

BlackBerry gets LogMeIn remote support

Rescue+Mobile lets a support technician take control of the handset   More...

Dell manufacturing plant

Dell planning factory closures to cut costs

Report claims that PC maker is looking to sell off...  More...

Google Chrome

More growing pains for Chrome

Google wrestles with licensing and security problems   More...

Smartphone

US takes 3G crown from Europe

Americans finally catch up with Europeans in adoption of 3G   More...

Primary Navigation