Update: You may also want to look at:更新:您可能也想要看看: MySpace Hack: How To View Any Users Private Videos myspace哈克:如何看待任何用戶的私人影片 . 。
Recently最近 Samy德薩米 [samy at namb dot la] released a worm ["Samy worm" or "JS.Spacehero worm"] in MySpace, popular social networking platform like Friendster, which caused him to be added as hero to millions of MySpace users (”but most of all, samy is my hero.”) as well as add him as their friend, all without their explicit permission. [德薩米在北美傳道部斑點香格里拉]發布了一個蠕蟲[ “德薩米蠕蟲”或“ js.spacehero蠕蟲” ]在MySpace上,流行的社交網絡平台一樣,和Friendster ,這使他增加一條,作為英雄,數以百萬計的MySpace上的用戶( “但最所有,德薩米是我的英雄“ ) ,以及添加他為他們的朋友,都沒有他們的明確許可。
After flooding the Network, MySpace stepped in and fixed the hole.水浸後,網絡,在MySpace上加強和固定孔。 Samy is still “hero” to millions of MySpace users in their profile.德薩米仍是“英雄” ,數以百萬計的MySpace上的用戶在他們的個人資料。
The purpose of this article is to highlight the security issues exposed by this worm.本文的目的是要強調安全問題所暴露出來的這種蠕蟲病毒。 It is definitely not limited to MySpace alone and the worm propagated not due to MySpace’s fault but fault of browser like Internet Explorer.這絕對不是僅限於MySpace上單獨和蠕蟲病毒傳播並不是因為MySpace上的故障,但故障的瀏覽器如Internet Explorer 。 And the flaw is waiting to be exploited in several other web applications of similar nature like Ryze or LinkedIn etc..和缺陷是等待被剝削,在其他幾個Web應用程序類似性質的一樣, ryze或LinkedIn的等。 In the remainder of this article I will summarize the modus-operandi of his script and suggest on ways to protect your web application against such attacks.在本文的其餘部分,我會總結的手法-的運作,他的腳本,並建議就如何保障您的Web應用程序對此類攻擊。
Read more (542 words) » 閱讀更多( 542字) »