Saturday, December 02, 2006

Zango (formerly 180 Solutions) connected to myspace virus

OK, follow the bouncing ball, it's a tricky one. You visit a scammers page on myspace. A Quicktime video on the page automatically runs. The video contains an href tag (whose damn dumb idea was it to a) include href tags in video files, and b) to follow those links automatically?)

The href tag contains javascript which overlays your myspace profile page with a fake login. If you use the fake login button, then you've been phished. The purpose of the phish seems to be to direct you to a collection of pornographic movies on the Zango web site.

For more details on the attack, see, Slashdot


