MySpace has been reportedly infected with a worm that directs users to a phishing site that steals the login-id and password to spread spam promoting adware sites.
The worm spreads by exploiting the Javascript support within Apple's QuickTime multimedia player. The JavaScript code then overlays the menu options on a MySpace profile with a bogus menu. When the user clicks any option on the bogus menu, he/she is directed to a fake log-in page hosted on another server, where his/her log-in details are captured.
Not only does the worm replace legitimate links on MySpace user profiles with links to the phishing site, but it also manages to root infected videos into the victims' profiles.
http://www.techtree.com/India/News/Worm_Attacks_MySpacecom/551-77648-643.html
The worm spreads by exploiting the Javascript support within Apple's QuickTime multimedia player. The JavaScript code then overlays the menu options on a MySpace profile with a bogus menu. When the user clicks any option on the bogus menu, he/she is directed to a fake log-in page hosted on another server, where his/her log-in details are captured.
Not only does the worm replace legitimate links on MySpace user profiles with links to the phishing site, but it also manages to root infected videos into the victims' profiles.
http://www.techtree.com/India/News/Worm_Attacks_MySpacecom/551-77648-643.html