View Full Version : MySpace users big targets for ID thieves


Janice
12-26-2006, 10:23 PM
http://news.yahoo.com/s/ap/20061225/ap_on_hi_te/myspace_security

MySpace users big targets for ID thieves

MySpace devotee Kary Rogers was expecting to see a gut-busting video when a friend from the popular online hangout messaged him a link.

First, though, he was directed to a page where he was supposed to re-enter his password. Rogers realized that someone was trying to steal his information, and he didn't take the bait. At best, he would be spammed with junk e-mails; worse, the Web thief might steal his real-life identity.

"I immediately went back and changed my password," said Rogers, 29, a network analyst for Mississippi State University in Starkville, Miss.

MySpace bills itself as a "place for friends." Increasingly, it is also a place for unfriendly attacks from digital miscreants on the prowl, luring users to sexually explicit Web sites, clogging mailboxes with spam messages and playing on the trust users have when speaking to "friends" to obtain passwords that could lead to identity theft.

Managing the risks that come with rapid growth is an enormous challenge for MySpace, now part of Rupert Murdoch's News Corp. media conglomerate. The site can't afford to drive away users, who might defect to one of a growing number of alternative sites, or advertisers, who pay top dollar to reach the growing MySpace audience.

Last month, MySpace inched past Yahoo Inc. (Nasdaq:YHOO - news) in U.S. page views, recording 38.7 billion, according to comScore Media Metrix.

A key reason behind the popularity is its ease. Simply by adding a few lines of computer code, users can create elaborate profiles and personalize them with photos, music and video. A host of communication tools makes it easy to send messages to one person or a whole list of friends, who number into the thousands for some of the more popular MySpace users.

Those same tools can be used by vandals to make it look like an innocent user has sent spam to the same long list of "friends."

Programmers are writing scripts that take advantage of specific features on MySpace, including "friend request," where one user asks to be added to another user's list of buddies.

One recent scam works this way: A spammer posts a number of phony profiles featuring pictures of cute women, often promising nude photos. A "friend request" with the woman's photo is sent to hundreds of users.

Once the fake profile loads, a blue screen descends, saying the profile is protected by the "MySpace Adult Content Viewer." Unsuspecting users who try to download the viewer instead get a worm that installs adware on their computers.

Social-networking sites make good targets because of the implicit level of trust users have when they're interacting with "friends."

"The ongoing interaction lowers your reservations and security barriers," said Marc Gaffan, an expert in online fraud and security at RSA, the security division of EMC Corp.

MySpace, which News Corp. bought last year for some $580 million, has recognized the threat and is stepping up security efforts, said Hemanshu Nigam, its chief security officer.

The company is rapidly expanding its team of software engineers, lawyers and other experts who look for suspicious activity, educate users on how to prevent attacks and go after the worst offenders.

Under Nigam's direction, the company recently formed a Content Assurance Team. Employees post fake profiles on the site, pretending to be vulnerable teens or clueless adults. The profiles are designed to keep tabs on everything from sexual predators to spammers.

MySpace also is preparing to launch a more aggressive education campaign, urging users to take care and use tools that restrict the viewing of their profiles to only trusted sources.

When all else fails, the company is also files civil suits and is increasing cooperation with law enforcement officials.

"We're trying to take away the 'cool' factor of trying to attack us," Nigam said.

Nigam came to MySpace after stints as a federal prosecutor specializing in child pornography and computer crime cases. He also led security efforts at Microsoft Corp. and the Motion Picture Association of America.

MySpace hired him in May to strengthen security and safety efforts at the site and other Internet properties owned by Fox Interactive media.

"Security is a top priority because it's critical for our community of users and for our business partners," Nigam said. "If advertisers feel uncomfortable being on a site that is seen as not as secure, not as safe, then we lose revenue."

So far, no major damage has been done on the site, although some users, increasingly annoyed by the fake friends and messages, are seeking other social networking alternatives.

"I don't have this problem on Facebook," Rogers said, referring to another popular site.

The Internet has weathered several threats over the years, but as users move on, so do the attackers.

Writers of malicious software used to count primarily on e-mail recipients to click on attachments to spread their wares. As e-mail recipients got more savvy, the writers looked to automate the process by exploiting vulnerabilities in e-mail programs, browsers and the Windows operating system from Microsoft Corp.

As those security holes get closed, virus writers are looking elsewhere, including social-networking sites attractive in part because of their size. "It's where the activity is and the attackers play the percentages," said David Cole, director of security response at Symantec Corp. "They go after the largest market share where there is the most activity."


http://d.yimg.com/us.yimg.com/p/net/20061225/capt.0ad31daac5e0acf234cb856200e9cdf6.jpg?x=180&y=119&sig=jZJlBYGxdAgbKyqEOMsgRA-- (http://news.yahoo.com/photo/ydownload_ap/20061225/photos_net_ap_tc/1167077510&g=events/tc/021406myspace)
MySpace.com co-founders Tom Anderson, left, and Chris Dewolfe pose for a photo July...

Hollow
12-26-2006, 11:07 PM
those stupid hackers send spam in bulletins on other people's accounts and try to make it sound like it's actually in the words of that person. they do a horrible job. an example:

Hey homie, I just downloaded some fly ass ringtone to my phone.
You've heard of those ringtones that only teens can hear...
Well anyone some managed to turn any song into this sound range so you can have any song as your ringtone now and adults can't hear it

I just installed 50 cents candy shop with this addition on it, hah my teachers didn't hear it but it bugged my friends during class. The teacher was wondering what was going on.

I got it from the site below, just click on the image

Jo_Luvs_Ketchup
12-26-2006, 11:08 PM
http://news.yahoo.com/s/ap/20061225/ap_on_hi_te/myspace_security

MySpace users big targets for ID thieves

MySpace devotee Kary Rogers was expecting to see a gut-busting video when a friend from the popular online hangout messaged him a link.

First, though, he was directed to a page where he was supposed to re-enter his password. Rogers realized that someone was trying to steal his information, and he didn't take the bait. At best, he would be spammed with junk e-mails; worse, the Web thief might steal his real-life identity.

"I immediately went back and changed my password," said Rogers, 29, a network analyst for Mississippi State University in Starkville, Miss.

MySpace bills itself as a "place for friends." Increasingly, it is also a place for unfriendly attacks from digital miscreants on the prowl, luring users to sexually explicit Web sites, clogging mailboxes with spam messages and playing on the trust users have when speaking to "friends" to obtain passwords that could lead to identity theft.

Managing the risks that come with rapid growth is an enormous challenge for MySpace, now part of Rupert Murdoch's News Corp. media conglomerate. The site can't afford to drive away users, who might defect to one of a growing number of alternative sites, or advertisers, who pay top dollar to reach the growing MySpace audience.

Last month, MySpace inched past Yahoo Inc. (Nasdaq:YHOO - news) in U.S. page views, recording 38.7 billion, according to comScore Media Metrix.

A key reason behind the popularity is its ease. Simply by adding a few lines of computer code, users can create elaborate profiles and personalize them with photos, music and video. A host of communication tools makes it easy to send messages to one person or a whole list of friends, who number into the thousands for some of the more popular MySpace users.

Those same tools can be used by vandals to make it look like an innocent user has sent spam to the same long list of "friends."

Programmers are writing scripts that take advantage of specific features on MySpace, including "friend request," where one user asks to be added to another user's list of buddies.

One recent scam works this way: A spammer posts a number of phony profiles featuring pictures of cute women, often promising nude photos. A "friend request" with the woman's photo is sent to hundreds of users.

Once the fake profile loads, a blue screen descends, saying the profile is protected by the "MySpace Adult Content Viewer." Unsuspecting users who try to download the viewer instead get a worm that installs adware on their computers.

Social-networking sites make good targets because of the implicit level of trust users have when they're interacting with "friends."

"The ongoing interaction lowers your reservations and security barriers," said Marc Gaffan, an expert in online fraud and security at RSA, the security division of EMC Corp.

MySpace, which News Corp. bought last year for some $580 million, has recognized the threat and is stepping up security efforts, said Hemanshu Nigam, its chief security officer.

The company is rapidly expanding its team of software engineers, lawyers and other experts who look for suspicious activity, educate users on how to prevent attacks and go after the worst offenders.

Under Nigam's direction, the company recently formed a Content Assurance Team. Employees post fake profiles on the site, pretending to be vulnerable teens or clueless adults. The profiles are designed to keep tabs on everything from sexual predators to spammers.

MySpace also is preparing to launch a more aggressive education campaign, urging users to take care and use tools that restrict the viewing of their profiles to only trusted sources.

When all else fails, the company is also files civil suits and is increasing cooperation with law enforcement officials.

"We're trying to take away the 'cool' factor of trying to attack us," Nigam said.

Nigam came to MySpace after stints as a federal prosecutor specializing in child pornography and computer crime cases. He also led security efforts at Microsoft Corp. and the Motion Picture Association of America.

MySpace hired him in May to strengthen security and safety efforts at the site and other Internet properties owned by Fox Interactive media.

"Security is a top priority because it's critical for our community of users and for our business partners," Nigam said. "If advertisers feel uncomfortable being on a site that is seen as not as secure, not as safe, then we lose revenue."

So far, no major damage has been done on the site, although some users, increasingly annoyed by the fake friends and messages, are seeking other social networking alternatives.

"I don't have this problem on Facebook," Rogers said, referring to another popular site.

The Internet has weathered several threats over the years, but as users move on, so do the attackers.

Writers of malicious software used to count primarily on e-mail recipients to click on attachments to spread their wares. As e-mail recipients got more savvy, the writers looked to automate the process by exploiting vulnerabilities in e-mail programs, browsers and the Windows operating system from Microsoft Corp.

As those security holes get closed, virus writers are looking elsewhere, including social-networking sites attractive in part because of their size. "It's where the activity is and the attackers play the percentages," said David Cole, director of security response at Symantec Corp. "They go after the largest market share where there is the most activity."


http://d.yimg.com/us.yimg.com/p/net/20061225/capt.0ad31daac5e0acf234cb856200e9cdf6.jpg?x=180&y=119&sig=jZJlBYGxdAgbKyqEOMsgRA-- (http://news.yahoo.com/photo/ydownload_ap/20061225/photos_net_ap_tc/1167077510&g=events/tc/021406myspace)
MySpace.com co-founders Tom Anderson, left, and Chris Dewolfe pose for a photo July...


What a coincidence! I'm being accused of hacking into a members AOL screen name! Could there be a connection? Hmmmmmm...

AKA
12-26-2006, 11:09 PM
It gets even worse than that. I've seen ones that advertise pills for, um... male problems.

Jo_Luvs_Ketchup
12-26-2006, 11:21 PM
It gets even worse than that. I've seen ones that advertise pills for, um... male problems.
I've seen that one lol. It's always from the same friend of mine. I was starting to wonder about her lol.

FOLrocks1
12-26-2006, 11:24 PM
That's horrible, but if people are going to post all of that personal information in the first place, that's dumb on their part.

Hollow
12-26-2006, 11:30 PM
It gets even worse than that. I've seen ones that advertise pills for, um... male problems.
hah yeah.

Subject: ALL Girls are Lying bigtime when they say that size doesen't matter, I got proof.... 59b74

Body: Heads up here for you guys, my best friend Pete has been getting all the girls at school and work after he has not had a girlfriend in the past 2 years. I asked him if he is drugging them or whatever so he told me his little secret. He has been taking these tablets, Click here so see where he gets them from they made his little magic stick grow almost double the size it was in about 2 months and he says it is still getting bigger.
I thought he was kidding around so I investigated a little bit into it and sure enough I found nine bottles of the these pills under his bed and to top that off, his 2 brothers are now taking them too, I don't know, but I am thinking now of buying them for you know who.. I know it sounds shallow but after seeing the results, it is hard to not do it. 4e0c4
I am telling you I have all the proof needed that they work, the place you order them from even guarentees that they will work on any guy or they give you what you paid right back. Don't pass up on this one guys, it is 100 onfirmed and for real. Get them while they are still available by clicking here 42a8

TJL
12-26-2006, 11:31 PM
It's amazing how many spam messages i get during a week on my myspace page. Half the time the profile is deleted before I even see a message in my inbox. Straight to the trash.

Czas na Zywiec
12-26-2006, 11:32 PM
If you're smart and don't click on those links you're fine. You know your friends and I'm sure you can tell them apart from spambots.

Hollow
12-26-2006, 11:32 PM
That's horrible, but if people are going to post all of that personal information in the first place, that's dumb on their part.
they don't do it on purpose....they get sent to a fake login page, thinking it's real, and log in.

Courtnee
12-27-2006, 12:06 AM
hah yeah.
omg. I hate that one. You can tell it's fake because it has the number/letter mumbo-jumbo in it.

dawsongirl
12-27-2006, 01:05 AM
I don't even go there much anymore....too much garbage and losers.

Karen*
12-27-2006, 06:18 AM
Ugh it gets so annoying. I learned this from a bulletin: One helpful tip that all MySpace users should follow is look for login.myspace.com in the URL field when they're typing in their email and password. Sometimes people will get a screen that looks like the login page. It's really a pop-up ad that's used as bait for people phish your passwords and info. If the URL doesn't say MySpace.com, don't put anything in. Press the Back button.

tdf4077
12-27-2006, 10:52 AM
Ugh it gets so annoying. I learned this from a bulletin: One helpful tip that all MySpace users should follow is look for login.myspace.com in the URL field when they're typing in their email and password. Sometimes people will get a screen that looks like the login page. It's really a pop-up ad that's used as bait for people phish your passwords and info. If the URL doesn't say MySpace.com, don't put anything in. Press the Back button.

Yup! I heard that too! I was hacked a little bit ago because I was directed to a new page and typed in my info not realizing otherwise...it was when I first got my myspace, and sometimes my computer is janky, so I thought it was legit enough...but when I saw weird things in my bulletin that I had evidently posted, I quickly changed my password and sent out a new bulletin apologizing/warning. Now, I change my password once every couple of weeks and my profile is set to secure most of the time.

Hollow
12-27-2006, 11:52 AM
Ugh it gets so annoying. I learned this from a bulletin: One helpful tip that all MySpace users should follow is look for login.myspace.com in the URL field when they're typing in their email and password. Sometimes people will get a screen that looks like the login page. It's really a pop-up ad that's used as bait for people phish your passwords and info. If the URL doesn't say MySpace.com, don't put anything in. Press the Back button.
exactly...either login.myspace.com or just myspace.com. there have been some smartasses thinking they can trick people who are careful of that by directing them to login-myspace.com, login.rnyspace.com, etc; and a few who set up profiles and made them look like login pages so that the link will show that the site is on myspace.com.

bottom line, you can certainly login to the myspace.com homepage, but any place you're directed to re-login at will be ONLY at login.myspace.com.

AKA
12-27-2006, 01:04 PM
Careful, though. I've seen "login.myspace.com.info." Make sure "login.myspace.com" is immediately followed by a slash ("/").

Courtnee
12-27-2006, 06:01 PM
http://c.myspace.com/Groups/00014/13/03/14493031_l.gif

Jo_Luvs_Ketchup
12-27-2006, 06:09 PM
http://c.myspace.com/Groups/00014/13/03/14493031_l.gif
:lol:

EmoJoe
12-27-2006, 11:01 PM
i seriously need to delete my myspace.

Courtnee
12-27-2006, 11:06 PM
i seriously need to delete my myspace.
ho