Collected research
MySpace QuickTime Worm
Hacker Protection from SQL Injection SPI Dynamics
SPI Labs brief on the December 2006 MySpace worm, which hid JavaScript in a QuickTime HREF track so playing an embedded movie ran the worm. It reinfected profiles over Ajax, replaced the MySpace navigation menu with a phishing lookalike, and spammed users. A second variant spread its payload across many hosts to resist takedown.
Record
- Document
- Hacker Protection from SQL Injection SPI Dynamics
- Published by
- spidynamics.com
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of spidynamics.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .