In case you missed it, a really nasty worm-like exploit using XSS (Cross Site Scripting) was discovered and used on Myspace.com earlier this month. The result was that the site experienced what was effectively a really powerful and rapidly escalating distributed denial of service (DDoS) attack.
The whole event was covered in articles on SecurityFocus, BetaNews, PCWorld, and ComputerWorld. There’s also an interview with the rather smug sounding prepetrator, “Samy”, on Google Blogoscoped.
The worm-like code didn’t use the Web site itself but rather tricked the site into allowing AJAX code to be loaded by browsers that had inadequate security.
All in all, this is simply a foretaste of what’s to come. As our Web technologies become increasingly sophisticated and complex we’re going to see lots more problems such as this one appearing.
Future assaults are likely to be launched not by smart-alecs like “Samy” who was simply trying to increase the number of people in his social network (using the worm he got more than one million before Myspace killed off his account). Nope, criminals and terrorists are likely to get into the game and what worries me is that they might already be doing so and we just haven’t noticed yet …
[Thanks to Backspin reader Lee Harrison for reminding to blog this.]




