Contents
What was the MySpace worm?
Samy (also known as JS. Spacehero) is a cross-site scripting worm (XSS worm) that was designed to propagate across the social networking site MySpace by Samy Kamkar. Within just 20 hours of its October 4, 2005 release, over one million users had run the payload making Samy the fastest-spreading virus of all time.
What did Samy Kamkar do?
In 2005, he created and released the fastest spreading virus of all time, the MySpace worm Samy, and was subsequently raided by the United States Secret Service under the Patriot Act….
| Samy Kamkar | |
|---|---|
| Nationality | American |
| Occupation | Privacy and security researcher, computer hacker, whistleblower and entrepreneur |
What is XSS worm scripting?
An XSS worm, sometimes referred to as a cross site scripting virus, is a malicious (or sometimes non-malicious) payload, usually written in JavaScript, that breaches browser security to propagate among visitors of a website in the attempt to progressively infect other visitors.
What happened to my space?
On February 11, 2016, it was announced that Myspace and its parent company had been bought by Time Inc. Time Inc. was in turn purchased by the Meredith Corporation on January 31, 2018. In May 2016, the data for almost 360 million Myspace accounts was offered on the “Real Deal” dark market website.
How did the Myspace breach happen?
According to Network World’s Howard Wen: “This haul contained usernames, passwords and IP addresses — the passwords had weak encryption. And many of these forums were running an old version of software with known security vulnerabilities that hackers can easily breach by using attack tools.”
Is MySpace still around 2020?
Yes, Myspace still exists and it is far from dead. It still has its Myspace domain up and running. Myspace was purchased and currently owned by Time Inc. since February 2016 and numerous redesigns and relaunches have occurred since then.
Can a stored XSS vulnerability cause a worm?
Stored XSS can be a very dangerous vulnerability since it can have the effect of a worm, especially when exploited on popular pages. For example imagine a message board or social media website that has a public facing page that is vulnerable to a stored XSS vulnerability, such as the profile page of the user.
Who is the creator of the Samy worm?
Samy (also known as JS.Spacehero) is an XSS worm that was designed to propagate across the MySpace social-networking site written by Samy Kamkar.
What was the payload of the Samy worm?
The worm itself was relatively harmless; it carried a payload that would display the string “but most of all, samy is my hero” on a victim’s MySpace profile page as well as send Samy a friend request.
Can a user accidentally trigger a XSS attack?
Users might accidentally trigger the payload if they visit the affected page, while a crafted url or specific form inputs would be required for exploiting reflected XSS. A stored XSS vulnerability can happen if the username of an online message board is not properly sanitized when it is printed on the page.