<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheets/rss.css" type="text/css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>The BFC Computing Weblog: New Myspace Worm?</title>
    <link>http://blog.bfccomputing.com/articles/2008/02/15/new-myspace-worm</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>My God, It's Full of Source!</description>
    <item>
      <title>New Myspace Worm?</title>
      <description>&lt;p&gt;I got a comment on myspace with the text:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;LOL you gotta see the new pics on her profile.
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;and a link to:&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;http://profile.myspace.com.index.cfm.fuseaction.user.viewprofile.friendid.518729090.cn/
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;which is a domain in china, registered &lt;a href="http://ewhois.cnnic.cn/whois?inputfield=value&amp;amp;value=518729090.cn&amp;amp;entity=domain&amp;amp;vcinput=9750&amp;amp;service=%2Fwhois"&gt;thusly&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;It looks like the standard MySpace login page.  Because MySpace is retarded and throws up login pages all the time at you, most users will assume this is valid.  I assume at that point it steals your password and propagates the worm.&lt;/p&gt;

&lt;p&gt;Perhaps on some machines it installs malware as well?&lt;/p&gt;

&lt;p&gt;I&amp;#8217;ll skip the pay-attention-to-your-URL&amp;#8217;s preaching, and suggest that writing buggy webapps puts your users at risk by teaching them bad habits.&lt;/p&gt;</description>
      <pubDate>Fri, 15 Feb 2008 18:43:00 -0500</pubDate>
      <guid isPermaLink="false">urn:uuid:d491bff0-8419-4fba-abe0-322c32e9d5fe</guid>
      <author>Bill McGonigle</author>
      <link>http://blog.bfccomputing.com/articles/2008/02/15/new-myspace-worm</link>
      <category>Internet</category>
      <category>Security</category>
      <trackback:ping>http://blog.bfccomputing.com/articles/trackback/4733</trackback:ping>
    </item>
  </channel>
</rss>
