- 10 Microsoft research projects
- 10 kitchen gadgets for the geek gourmet
- Verizon trounces competition
- Smartphone smackdown: Storm vs. iPhone
- FBI warns of holiday cyber scams
The MySpace page of pop singer Alicia Keys appears to have been hacked and is emitting exploit code that can trick visitors to the page, according to a security vendor.
The MySpace page appears to have been compromised with an image of 8,000 pixels by 1,000 pixels, like a blank image, says Roger Thompson, a researcher at Exploit Prevention Labs. “The blank image is overlapping the page,” he says. “It’s in the background. If you happen to click on it, it takes you off to a place in China, which tries to get exploits into your system.”
Someone clicking the Keys page at random might touch the exploit image and be presented with a page that says you need an ActiveX control to see the page, Thompson says. “It’s a trick to get you to click on it and receive malicious code.”
Thompson, a malware expert, says it’s the first time he’s seen this type of image-based exploit code, which he describes in this video. Thompson says it isn’t clear whether just a few pages on MySpace have been compromised in some way or whether there’s a broader hack of MySpace.
Exploit Prevention Labs has notified MySpace about the issue. Other bands on the MySpace entertainment page that appear to have been hit by a similar exploit are Greements of Fortune, a French funk band, and Dykeenies, a rock band from Glasgow.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comments (1)
RE: Hackers target Alicia Keys MySpace pageBy Lani on November 19, 2007, 7:55 pmThis problem is much more rampant than you think. The blank image-based hack has been used in many of my friends accounts. I'm a bit surprised it's happened to...
Reply | Read entire comment
View all comments