Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > General Security

General Security Post any general questions related to security, viruses or spyware here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 27th July 2006   #1
SuperGeek
 
TeMerc's Avatar
 
Profile:
Join Date: May 2006
Location: PHX. AZ
Posts: 3,311
Computer Experience:
Intermediate
TeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation LevelTeMerc Reputation Level


F-Secure Finds Exploits At Social Networking Sites

Quote:
Web Application Worms exploit persistent Cross Site Scripting (XSS) vulnerabilities in websites. It's a new category of malware and it's a growing concern for popular websites. Social Networking sites seem to be the most popular target as of now. MySpace has already been hit by two such worms - the Samy worm in October last year and last week's Flash worm. Samy was written by a guy who wanted to become popular on MySpace. So he designed the worm to crawl through the site while furiously adding people to his friends list. The result: over a million "friends" in a couple of hours. Last week's worm exploited a vulnerability in Macromedia Flash to redirect MySpace users to an objectionable webpage.

Last week MySpace was also the target of a malicious banner advertisement that ran on the site. It used the WMF vulnerability in Windows to serve adware to more than a million users with unpatched machines.

All this piqued our interest and we decided to see how secure other popular social networking sites are against "wormable" XSS vulnerabilities. We picked two among the top social networking sites with a reported combined user base of 80 million. Within half an hour we had discovered over half a dozen potentially "wormable" XSS vulnerabilities in each site! We stopped looking after finding half a dozen, but we are sure there are a lot more holes in there. With about a day's work a malicious attacker with a half-decent knowledge of javascript could create a worm using just one of these vulnerabilities.

Something to consider: The WMF banner ad successfully reached about one million users. An automated worm utilizing a similarly malicious WMF exploit or a similar browser expoit (maybe even a 0-day exploit) could potentially reach a much, much larger audience of unpatched machines. Theoretically, this could be the entire user base...

Recommendations -
  • 1. End users need to patch their machines. There's no excuse not to.
    2. Web application developers must start taking security seriously. Yes, XSS issues are silly, easy to find and omnipresent. And XSS issues have stopped being funny for a long time now. They are a real danger with the advent of Phishing and Web Application worms that exploit a mass user base of millions of users within a very short time.

Of course, we have reported the issues to the affected websites and are working with them to get the issues fixed. And, of course, we aren't taking any names here.
F-Secure Blog

TeMerc is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
New Tool To Scan Sites For Exploits TeMerc General Security 7 23rd July 2006 21:05
Cannot Get Windows Updates or Visit Secure Sites KauaiTim Internet Explorer 9 3rd January 2006 20:55
can't access 'secure' internet sites Jim Sturley Windows 95/98/Me/NT 1 3rd May 2005 23:15
secure sites flylioness Internet Explorer 5 27th April 2003 22:47
Can not access secure sites. No log-ons available. edward1c Internet Explorer 3 24th December 2002 00:44


All times are GMT +1. The time now is 13:54.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]