Newsletter:

Skip Navigation LinksHome > News > Security > Hackers attack MySpace and Facebook

Hackers attack MySpace and Facebook

By Clement James
4 March 2008 07:35AM
Tags: hackers | attack | myspace | facebook

Buffer overflows are at the heart of a series of attacks against Facebook and MySpace, security firm Fortify Software has warned..

Criminal hackers now view social networking sites as their best target for attacks, according to Rob Rachwald, director of product marketing at Fortify Software.

Part of the reason is that such sites are designed to be usable by "unsophisticated" consumers, meaning that the barrier to entry for attacks is potentially lower as users are more likely to click on a link that leads to malware.

"A buffer overflow enabled hackers to exploit the Aurigma ActiveX image uploading software used by Facebook, MySpace and other social networking sites," said Rachwald.

"The bad news is that this exploit is being used in a hacker toolkit currently being offered for download on several Chinese language sites, meaning that novices have been able to stage these attacks, and not just professional hackers."

Rachwald argued that social networking sites can no longer limit protection to their own security practices, but must take in the practices of their suppliers.

"Had Facebook and MySpace required Aurigma to provide proof of a code audit before sourcing the plug-in this latest security issue could have been avoided," he said.

Copyright © 2008 vnunet.com

   


Ads by Google


See web apps on the desktopDoes your security solution create work for you? Go Websense.
No hardware. No Software. No Fuss.
click here


Product Reviews

Star Rating
LogLogic's LX 2010 provides customers with a good feature set for network forensic investigations.
Star Rating
WetStone's LiveDiscover is an interesting proposition. It is designed as a first step in locating target...
Star Rating
This package from 8e6 Technologies offers high flexibility for the large enterprise. The bundle consists of...
Star Rating
Bringing together some of Trend Micro's features from its larger appliance-based systems, the InterScan Web...
Star Rating
Clearswift's MIMEsweeper appliance takes web content management to the next level. This device is loaded with...
ITNews NetSeminars
TopTopics
(26233) -  supercomputer
(8014) -  microsoft
(6009) -  telstra
(5916) -  broadband
(5887) -  internet
(5615) -  web
(5167) -  australia
(4395) -  iphone
(3789) -  security
(3486) -  google
(3385) -  windows
(3238) -  data
(3012) -  apple
(2709) -  software
(2693) -  yahoo