Update: You may also want to look at: MySpace Hack: How To View Any Users Private Videos.
Recently Samy [samy at namb dot la] released a worm ["Samy worm" or "JS.Spacehero worm"] in MySpace, popular social networking platform like Friendster, which caused him to be added as hero to millions of MySpace users ("but most of all, samy is my hero.") as well as add him as their friend, all without their explicit permission.
After flooding the Network, MySpace stepped in and fixed the hole. Samy is still "hero" to millions of MySpace users in their profile.
The purpose of this article is to highlight the security issues exposed by this worm. It is definitely not limited to MySpace alone and the worm propagated not due to MySpace's fault but fault of browser like Internet Explorer. And the flaw is waiting to be exploited in several other web applications of similar nature like Ryze or LinkedIn etc.. In the remainder of this article I will summarize the modus-operandi of his script and suggest on ways to protect your web application against such attacks.
Full article (545 words) »