QuickTime JavaScript worm spreads via MySpace

Websense Security Labs has confirmed the existence of a worm spreading on the MySpace network. This worm is exploiting the Javascript support within Apple’s embedded QuickTime player. This is used in conjunction with a MySpace vulnerability that was announced two weeks ago on the Full-Disclosure mailing list. The vulnerabilities are being used to replace the legitimate links on the user’s MySpace profile with links to a phishing site.

Once a user’s MySpace profile is infected (by viewing a malicious embedded QuickTime video), that profile is modified in two ways. The links in the user’s page are replaced with links to a phishing site, and a copy of the malicious QuickTime video is embedded into the user’s site. Any other users who visit this newly-infected profile may have their own profile infected as well.

An infected profile can be identified by the presence of an empty QuickTime video or modified links in the MySpace header section, or both.

More info and screenshot: http://www.websense.com/securitylabs/alerts/alert.php?AlertID=708

F-Secure Virus Information:
Name: JS/Quickspace.A
Type: Worm
Category: Virus
Platform: JS (JavaScript)

More info: http://www.f-secure.com/v-descs/js_quickspace_a.shtml

37 Comments

  1. Clearly someone wants to drive business to their security site. Check the two “Detection Methods” and “Prevention Methods” links. I have seen no clear description of exactly how it spreads and if it spreads via user interaction, then it’s something I don’t need to worry about.

  2. I followed the link to GNUCITIZEN. So, is this a worm only because the kinds of people that use social networking sites are so starved for attention that they’d click on ANYTHING to make a connection to someone?

    Seems like phishers have found ripe ground where the gullible congregate.

  3. So this is a Quicktime in IE issue?

    Not only that but you must have a profile in MySpace and log in to it!

    So, make it like this:

    So this is a Quicktime in IE issue in MySpace profiles?

    Note the word SPREADING like this is one of the common Winblows hits Melissa and ILOVEYOU…

  4. No one with any sense has ever claimed that OS X is invincible, but I love it how some people jump with joy over news of a possible OS X security exploit, as though even a single bonafide OS X worm/virus proves that OS X is just as insecure as Windows. Beyond ridiculous!

  5. This appears to be a phishing attack that alters (once allowed) the HREF track in Quicktime movies (and probably the HTML of the host’s page)-

    “An HREF track is a special type of text track that adds interactivity to a QuickTime movie. HREF tracks contain URLs that can specify movies that replace the current movie, load another frame, or that load QuickTime Player. They can also specify JavaScript functions or Web pages that load a specific browser frame or window.”

    – but I’ll wait for more info from more knowledgeable people.

    I’m not a kid no more, so I don’t bother with MySpace.

  6. Wow!

    That didn’t take long to turn this around and blame Windows! You all always seem to surprise me!

    It’s an IE issue because it comes through their browser. However, Apple makes the software that the worm spreads through….

    So, it’s also a QuickTime issue.

    Own up to it.

Reader Feedback

This site uses Akismet to reduce spam. Learn how your comment data is processed.