NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Incidents

Incidents


Flash-Based Social Networking Worm Rampages on LiveJournal

Steals email addresses and lowers privacy settings

By Lucian Constantin, Web News Editor

24th of September 2009, 13:42 GMT

Adjust text size:


Social networking worm hits LiveJournal
Enlarge picture
Users of the LiveJournal blogging platform were the target of a malicious attack on Tuesday, when a social networking worm that spread by simply viewing an infected post was released on the website. The malware stole email addresses and made private blog entries accessible to everyone.

The LiveJournal staff has posted a detailed announcement describing the attack, which is said to have only lasted for less than two hours. As a result, the ability to embed video files into blog entries has been suspended, but has since been restored for a few trusted services such as YouTube.

The social networking worm propagated through an embedded flash video that used the allowScriptAccess parameter to trigger a cross-site scripting condition. According to Adobe, "When AllowScriptAccess is 'always,' the SWF file can communicate with the HTML page in which it is embedded even when the SWF file is from a different domain than the HTML page."

Upon viewing an already infected posting, the exploit proceeded to compromising the account of the visitor by adding the malicious code to their latest entry, resetting its icon and metadata, as well as setting its security to public so that it could be viewed by everyone. Additionally, the email address registered with the account was recorded and possibly uploaded to a third-party server.

"Through reports and our investigation this evening, we've seen fewer than 100 affected entries; however, due to the nature of friends pages it is likely more widespread than this," the LiveJournal staff note. All users are advised to check if their latest blog entries contain four blocks of embedded Flash at the end. According to an LJ user who analyzed the attack, the code is of the form:

CODE
<lj-embed id="26">
<object width="1" height="1">
    <param name="movie" value="LINKTOBADFLASH"></param>
    <param name="wmode" value="transparent"></param>
    <param name="allowScriptAccess" value="always"></param>
    <embed src="LINKTOBADFLASH" type="application/x-shockwave-flash" width="1" height="1" wmode="transparent"></embed>
</object>
</lj-embed>


This threat bears striking similarities to the Pinkren worm discovered on the Renren Chinese social network at the end of August. There is no indication that the LiveJournal worm attempted to infect computers with malware, which actually intrigued security researchers, according to The Register.

TAGS:

LiveJournal | social networking worm | AllowScriptAccess | cross-site scripting | email harvesting
Read by 965 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 1 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Vulnerabilities Found in Four More Top 20 Facebook Applications

New Koobface Variant Drops Scareware and Click Fraud Malware

New Chinese Social Networking Worm Discovered

Koobface Morphs and Becomes More Resilient

Koobface Rampages on Twitter

Twitter's API Used to Create Worm

Mikeyy's Worms Hit Twitter for the Fourth Time

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM