pf » MySpace Hacked with CSRF and XSS
October 13, 2005
MySpace Hacked with CSRF and XSS
It seams that someone recently hacked myspace.com, the ColdFusion powered community site with millions of users.
An aquaintance of mine recently managed within 24 hours to become the most popular civilian on myspace with the help of a clever bit of viral javascript imbedded into his myspace page.
By the time myspace shut down their site for a few hours to investigate he had over 1 million requests from unknowing myspace members for him to be listed as their myspace friend.
Because he was able to embed javascript into his profile, that makes it a XSS, or cross site scripting attack. And because he was able to take advantage of a other users login and perform a function on their behalf (by either submitting a form, or calling a url), it was also a CSRF, or cross site request forgery attack.
Related Entries
- Announcing Web Application Firewall for ColdFusion - July 9, 2007
- Risks of FCKeditor Vulnerability in CF8 - July 6, 2009
- Firefox 3.5 Introduces Origin Header, Security Features - June 30, 2009
- Tips for Secure File Uploads with ColdFusion - June 24, 2009
- CFPARAM for Simple String Validation - May 29, 2007
Trackback Address: 483/8256350ED1F0319C5936D401253E7699
Comments
On 10/13/2005 at 1:35:24 PM EDT Dan G. Switzer, II wrote:
1
While this sounds like a coding issue more than anything, any idea if MySpace is now on New Atlanta's BlueDragon, or are they still on Macromedia's CF?
Part of me can't help but wonder if there's going to be some political finger pointing...
On 10/13/2005 at 1:41:09 PM EDT Pete Freitag wrote:
2
These are definitely coding issues, it doesn't really matter that their site is CFML, you could have this problem on any app server.
On 10/13/2005 at 2:22:21 PM EDT Barney wrote:
3
I seem to recall saying bad things about MySpace's development techniques a while ago.... Seems things are still kind of sketchy. Not to mention taking down their whole site to investigate.
On 10/20/2005 at 2:46:39 PM EDT Roger wrote:
4
The tech is in a whitepaper http://www.bindshell.net/papers/xssv.html
On 05/29/2006 at 8:15:20 PM EDT Chris Shiflett wrote:
5
This might surprise you, but you're one of the few people who can accurately categorize this attack - well done! :-)
On 06/19/2006 at 6:51:40 PM EDT A nonymous wrote:
6
Problem. He didnt take advantage of your login, since you were already logged in, there was no need to do so. He should of been smart about it and stole all your cookies. Then everyone would be owned.
On 02/04/2007 at 11:38:44 PM EST levern wrote:
7
Hello im currently looking for a website designer to build me a web site simuliar to www.myspace.com I'M aware that myspace was built in coldfusion.. please email me back & let me know if you can do this project? MY EMAIL ADD IS levern.green@gmail.com SERIOUS INQUIRIES ONLY !
- J2EE Session Cookies on ColdFusion / JRun
- Hands on ColdFusion Security Training
- ColdFusion 9 Solr Vulnerability - Are you at Risk?
- FCKEditor Year 2010 Bug for Firefox 3.6
- jQuery UI Sortable Tutorial
- CFLogin Security Considerations
- Use varchar(max) instead of text in SQL Server
- ColdFusion SOAP Web Services and onRequestStart
Subscribe to my RSS Feed:
RSS
RSS

add to del.icio.us
Pete Freitag is a software engineer, and web developer located in











