Samy opens new front in worm war

By Munir Kotadia, ZDNet Australia
Tuesday, October 18, 2005 11:26 AM

The newly discovered Samy worm is one of the first to exploit a cross-site scripting vulnerability, a technique security experts fear could be used to open a new front in attacks.

Samy is a self-propagating worm that appears to have been written by a member of MySpace.com, a community site dedicated to helping friends stay in touch and share pictures. By exploiting vulnerabilities in the MySpace.com site, the worm added a million users to the author's "friends" list.

Although the worm is no threat to other Web sites, security experts say the new self-propagating cross-site scripting (XSS) worm will likely be copied by other writers of malicious software.

Adam Biviano, senior systems engineer at Trend Micro Australia and New Zealand, explained that the MySpace.com user--called Samy--had created a "malicious" profile by taking advantage of a flaw in the Web site's design. The profile, when viewed, automatically activated code to add the visitor to Samy's "friends" list.

Additionally, the malicious code would be copied into the victim's profile, so that when that person's profile was viewed, the infection spread.

"The infection stays on the Web site and almost creates a denial-of-service attack, because there is an exponential explosion of entries in your friends list that will eventually consume the resources of the infrastructure," Biviano said.

Scott Chasin, chief technology officer at MX Logic, said that although cross-site scripting vulnerabilities have been recognized for some time, this is the first worm he has come across that was designed to exploit one.

"This attack highlights the opportunity for a self-propagating worm to take advantage of XSS technologies...The vulnerability leveraged by Samy allows code to be injected into Web sites with the aim of being parsed and/or executed by Web browsers or e-mail clients," he said.

Chasin said that worms taking advantage of cross-site scripting flaw will become more common as browsers and e-mail applications evolve.

"The XSS worm threat is only becoming more relevant as the sophistication of browsers and the underlying technologies being rendered by them continue to saturate the Internet through blogs and e-mail applications," he said.

"They could have a significant impact for Internet continuity…including distributed denial of service attacks, spam attacks and dissemination of browser exploits," Chasin added.

Trend Micro's Biviano said administrators should take note, because this creates yet another method of attack.

"It is definitely something to consider is you are an application designer or a Webmaster. It is another security issue you need to contend with," he said. "You don't want the ability for a loop like this to be created that will end up causing a denial of service on your Web site."


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Maintaining an online presence in Jabber

Web Development

Follow these steps to maintain a presence in the Jabber online community, such as retrieving a list of friends from the roster.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? Let Dr David Scott from Intel take you a for quick tour on developing HPC applications.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajen from Oracle highlights the important considerations ...
    Play video


  • HPC Architecture: Explained

    Why is High Performance Computing increasingly in demand in today's businesses? Find out which is the most widely deployed HPC architecture today.
    Play video

Tags

  1. apps
  2. attack
  3. attacks
  4. bank
  5. botnet
  6. card
  7. cisco
  8. data
  9. details
  10. dns
  11. facebook
  12. fix
  13. flaw
  14. flaws
  15. google
  16. id
  17. malware
  18. microsoft
  19. patches
  20. researcher
  21. researchers
  22. risk
  23. security
  24. symantec
  25. uk
  26. update
  27. updates
  28. us
  29. vmware
  30. warns

A recessionary sense of déjà vu

Blog thumbnail

Depending on which camps you speak to, the U.S. credit meltdown could either spell bad news for IT wages or have little impact on tech spending in Asia.

And depending..... by Eileen Yu

Read more »