Computerworld
Alicia Keys' MySpace page sings with malicious code
The MySpace pages for singer Alicia Keys and other musicians were hacked with a seemingly new type of hack, a security expert said Thursday.
Steven Schwankert (IDG News Service)  09 November, 2007 14:31

The MySpace pages for singer Alicia Keys and other musicians were hacked with a seemingly new type of hack, a security expert said.

Keys' MySpace page and that of others, including a Scottish band and a French band, were flagged by users of Exploit Prevention Labs' LinkScanner software, which blocks pages containing malicious code. The discovery came after users began reporting that Keys' page was blocked, according to Roger Thompson, chief technology officer of LinkScanner.com.

"When we saw it was MySpace and Alicia Keys, we took a good look at it," he said in an interview.

When a visitor views the page, an exploit first attempts to install malware on the visitor's computer if it is not properly patched. Thompson said he was not sure yet which flaw the malware was looking to exploit. If that is not successful, the user is then asked to install a fake codec to view a video. Thompson explains the process in this video.

If both of those should fail, the user is also vulnerable if he or she clicks anywhere on the page that is not a legitimate link--including the ads. "If your mouse slips a bit from what you meant to click, you get the background [link]," which references a site based in China, co8vd.cn, and also attempts to install malicious code. Thompson said he had not seen that kind of "image-background link" before.

The domain is registered to Xiamen Hua Shang Sheng Shi Network, in the coastal city of Xiamen in Fujian province, according to the China Internet Network Information Centre's WHOIS listing. The company could not immediately be contacted for comment.

Because the attack affected several different pages, including one of a high-profile figure like Keys, Thompson believes this is a hack of MySpace, and not a case of attackers simply uncovering the user names and passwords for those pages.

MySpace said it had already taken care of the problem.

"Individuals who try to phish our members are violating the law and are not welcome on MySpace. We have blocked and removed the source of this phishing attempt and restored the profile," a MySpace spokesperson said by e-mail. Thompson confirmed that the Keys page was now clean, but added, "We'll see what happens over the next few days."

The hackers success with Keys' page, which Thompson described as "lucky," couldn't come at a better time for them--or worse for the musician. Keys, a Grammy Award-winning singer with several platinum albums, will put out her latest release, "As I Am," on November 13.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

Top 10 Ways to Increase IT ROI Without Adding Staff

Today, IT managers are looking for alternative strategies to increase their IT ROI. The first principle is: Simplify operations. Read this white paper for 10 specific strategies for increasing IT ROI.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.