Not Much Money In MySpace Ads... But How About Some Spyware!
from the oops dept
While MySpace hasn't been able to do much to capitalize on all of those banner ad impressions the site is supposedly getting, it appears that others are figuring out how to monetize it for them. The latest is that some scammers figured out how to use a vulnerability to serve up spyware to MySpace visitors through (you guessed it) all of those ad banners. The researcher who discovered this claims the spyware got installed on over a million computers -- exploiting a flaw that Microsoft had patched months ago. Of course, this isn't the first time that MySpace has been used to distribute spyware. It seems that, even if Rupert Murdoch doesn't figure out how to squeeze a lot of money out of MySpace, scammers will do their best to do it for him.


Reader Comments
(Flattened / Threaded)
yo
FIRST!
(reply to this comment) (link to this comment)
Re: yo
This has to stop if you don't have anything to say about the article don't post im tired of this what this says to me is that you have no life and surf the internet all day to find things that you can be first on well you know what stop it's meaningless and is Annoying as all hell
Thank you
(reply to this comment) (link to this comment)
Re: Re: yo
The senseless post by Guy should be deleted!
(reply to this comment) (link to this comment)
Re: Re: yo
Have you ever heard of a "period"???????
(reply to this comment) (link to this comment)
Re: Re: yo
PLEASE, stop feeding the trolls. Eventually they'll get hungry and wander over to Slashdot.
(reply to this comment) (link to this comment)
Re: Re: Re: yo
No they won't. We got linked to slashdot once and now they're wandering over here.
This crap has got to stop. Techdirt simply needs to enable moderation and registration and remove anonymous posting.
This site is built on the same stuff as slashdot (it used to be anyway), it shouldn't be hard.
Or just pick some volunteer moderators to delete posts they deem as "crappy".
Or just do a regexp for *first* on the first 3 posts made, if it's in there it doesn't get posted and the IP of the person posting gets added to the httpd.conf's denied list. (PS, that's a joke)
(reply to this comment) (link to this comment)
redirects
In addition to spyware, I have personally seen profile redirects to myspace lookalike pages.
(reply to this comment) (link to this comment)
Re: redirects
And people put in their emails and passwords then say "OMG. My MySpace got hacked!"
(reply to this comment) (link to this comment)
YO
DUMBASS
(reply to this comment) (link to this comment)
yo yo
SECOND!!
(reply to this comment) (link to this comment)
It's just natural selection in progress.
(reply to this comment) (link to this comment)
yo yo yo
SIXTH!
(reply to this comment) (link to this comment)
Does anyone know if it is in Mozilla or in IE or both?
(reply to this comment) (link to this comment)
Use IE!
(reply to this comment) (link to this comment)
Have you seen my ball?
(reply to this comment) (link to this comment)
I second that.
Throw Guy out. We could always wheel him down to the river and drop him in. Post something useful and we'll use it.
(reply to this comment) (link to this comment)
I have never seen so much spam in one place.
Yet, I contribute, for there is absolutely nothing worth saying about this aricle.
(reply to this comment) (link to this comment)
Mike or anybody else, I dont get how somebody can access the advertisments in myspace and load them with spyware or are we saying they already had it in them?
(reply to this comment) (link to this comment)
on the topic of the flaw. I am an avid myspace user and I am glad to being using FireFox because I am still spyware free.
(reply to this comment) (link to this comment)
lol..
What gets me most is that MySpace doesn't screen ads before they put them on. I mean if it really was malware code they should have easily been able to find it in the code. Oh well, I use SlimeBrowser and rarely ever get SpyWare. Fucking idiots who use Internet Exploder -_-...
But, people who spam with "first!" and bullshit like that, that gives nothing to the topic should just be IP banned. Most of them wouldn't even know how to get around it anyways -_-
That's my two cents.
(reply to this comment) (link to this comment)
httpd.conf?
is that a Linux thing? This site is run on Windows Server 2003 Web Edition!
Oh and I almost forgot....
21ST!!!!
(reply to this comment) (link to this comment)
Re: httpd.conf?
> This site is run on Windows Server 2003 Web Edition!
http://toolbar.netcraft.com/site_report?url=http://www.techdirt.com
looks like linux to me...
(reply to this comment) (link to this comment)
Sean, you are an idiot. SlimBrowser is a shell for Internet Explorer.
(reply to this comment) (link to this comment)
T get back on the subject
I use Mysace almost everyday and I never realized until this articles they were having so many problems. Thank God I have a Kick Ass fire wall so far so good on my PC.
And at first when I read this article it did amaze me that MySpace doesn't screen ads before they go up. But then I thought that there is little to no screening b/c there are all these backlashes on kids putting up half nude pictures.. So I am not too surprised... Just irritated.
But I still love Myspace and I am not giving it up.
(reply to this comment) (link to this comment)
Great, I'm going to have to check and clean the kids computers. For some reason they still use IE, even though Firefox is right there for them to use.
BTW: Last post! For the moment
(reply to this comment) (link to this comment)
Lay Person
Looks like everyone is confused!
The Flash Player plugin versions
(reply to this comment) (link to this comment)
Lay Person
Looks like everyone is confused!
The Flash Player plugin, versions 8 or less, are the culprit. All those fancy images that move around on your screens and in the ads use an application called Flash owned by Adobe Systems.
Get and install Flash Player 9. This will correct the flaw. It doesn't matter whether it's IE or Firefox they both use this application hence they are both vulnerable.
What happens is that when the Flash Player loads there is a brief window of time where the player allows code to enter a users machine thereby rendering it's destructive path.
That's pretty much it in lay terms.
Good luck!
(reply to this comment) (link to this comment)
yeah!
I just wanted to say 28TH!!!...since everyone else was doing it :]
(reply to this comment) (link to this comment)
Add Your Comment