Web Hack List

Collected research

MySpace QuickTime Worm

Hacker Protection from SQL Injection – SPI Dynamics

SPI Labs brief on the December 2006 MySpace worm, which hid JavaScript in a QuickTime HREF track so playing an embedded movie ran the worm. It reinfected profiles over Ajax, replaced the MySpace navigation menu with a phishing lookalike, and spammed users. A second variant spread its payload across many hosts to resist takedown.

Record

Document
Hacker Protection from SQL Injection – SPI Dynamics
Published by
spidynamics.com
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of spidynamics.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .