Update: You may also want to look at:更新:您可能也想要看看: MySpace Hack: How To View Any Users Private Videos myspace哈克:如何看待任何用户的私人影片 . 。
Recently最近 Samy德萨米 [samy at namb dot la] released a worm ["Samy worm" or "JS.Spacehero worm"] in MySpace, popular social networking platform like Friendster, which caused him to be added as hero to millions of MySpace users (”but most of all, samy is my hero.”) as well as add him as their friend, all without their explicit permission. [德萨米在北美传道部斑点香格里拉]发布了一个蠕虫[ “德萨米蠕虫”或“ js.spacehero蠕虫” ]在MySpace上,流行的社交网络平台一样,和Friendster ,这使他增加一条,作为英雄,数以百万计的MySpace上的用户( “但最所有,德萨米是我的英雄“ ) ,以及添加他为他们的朋友,都没有他们的明确许可。
After flooding the Network, MySpace stepped in and fixed the hole.水浸后,网络,在MySpace上加强和固定孔。 Samy is still “hero” to millions of MySpace users in their profile.德萨米仍是“英雄” ,数以百万计的MySpace上的用户在他们的个人资料。
The purpose of this article is to highlight the security issues exposed by this worm.本文的目的是要强调安全问题所暴露出来的这种蠕虫病毒。 It is definitely not limited to MySpace alone and the worm propagated not due to MySpace’s fault but fault of browser like Internet Explorer.这绝对不是仅限于MySpace上单独和蠕虫病毒传播并不是因为MySpace上的故障,但故障的浏览器如Internet Explorer 。 And the flaw is waiting to be exploited in several other web applications of similar nature like Ryze or LinkedIn etc..和缺陷是等待被剥削,在其他几个Web应用程序类似性质的一样, ryze或LinkedIn的等。 In the remainder of this article I will summarize the modus-operandi of his script and suggest on ways to protect your web application against such attacks.在本文的其余部分,我会总结的手法-的运作,他的脚本,并建议就如何保障您的Web应用程序对此类攻击。
Read more (542 words) » 阅读更多( 542字) »