Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Incidents

September 24th, 2009, 13:42 GMT · By

Flash-Based Social Networking Worm Rampages on LiveJournal

SHARE:

Adjust text size:


Social networking worm hits LiveJournal
Enlarge picture
Users of the LiveJournal blogging platform were the target of a malicious attack on Tuesday, when a social networking worm that spread by simply viewing an infected post was released on the website. The malware stole email addresses and made private blog entries accessible to everyone.

The LiveJournal staff has posted a detailed announcement describing the attack, which is said to have only lasted for less than two hours. As a result, the ability to embed video files into blog entries has been suspended, but has since been restored for a few trusted services such as YouTube.

The social networking worm propagated through an embedded flash video that used the allowScriptAccess parameter to trigger a cross-site scripting condition. According to Adobe, "When AllowScriptAccess is 'always,' the SWF file can communicate with the HTML page in which it is embedded even when the SWF file is from a different domain than the HTML page."

Upon viewing an already infected posting, the exploit proceeded to compromising the account of the visitor by adding the malicious code to their latest entry, resetting its icon and metadata, as well as setting its security to public so that it could be viewed by everyone. Additionally, the email address registered with the account was recorded and possibly uploaded to a third-party server.

"Through reports and our investigation this evening, we've seen fewer than 100 affected entries; however, due to the nature of friends pages it is likely more widespread than this," the LiveJournal staff note. All users are advised to check if their latest blog entries contain four blocks of embedded Flash at the end. According to an LJ user who analyzed the attack, the code is of the form:

CODE
<lj-embed id="26">
<object width="1" height="1">
    <param name="movie" value="LINKTOBADFLASH"></param>
    <param name="wmode" value="transparent"></param>
    <param name="allowScriptAccess" value="always"></param>
    <embed src="LINKTOBADFLASH" type="application/x-shockwave-flash" width="1" height="1" wmode="transparent"></embed>
</object>
</lj-embed>


This threat bears striking similarities to the Pinkren worm discovered on the Renren Chinese social network at the end of August. There is no indication that the LiveJournal worm attempted to infect computers with malware, which actually intrigued security researchers, according to The Register.

TELL US WHAT YOU THINK:

2,260 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Vulnerabilities Found in Four More Top 20 Facebook Applications

New Koobface Variant Drops Scareware and Click Fraud Malware

New Chinese Social Networking Worm Discovered

Koobface Morphs and Becomes More Resilient

Koobface Rampages on Twitter

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM