Got a tip for us? Share it...

MySpace Demands Apple Change Quicktime To Fix MySpace Worm

According to News.com, MySpace.com is demanding that Apple change its Quicktime player software to address an issue that occurred recently when the popular social networking website was attacked by a phishing/worm attack that used embedded Quicktime movies to propagate.

The worm exploits a common type of Web vulnerability called a cross-site scripting flaw in the site along with a feature called HREF track in QuickTime that has legitimate uses but can also be abused, experts said.


Nevertheless, Apple is obliging.

Apple is working on a QuickTime fix, but has a temporary solution available Tuesday, company spokeswoman Lynn Fox said in an e-mail.

"Recently we learned about an issue that exploits a feature in QuickTime used to target MySpace users. We have devised a way to disable this QuickTime feature for those who use Internet Explorer. We are working on a broader solution for all other users as well," Fox said in the e-mail.

Apple said it has provided MySpace with the temporary fix. The computer company said it would be up to the social-networking site to offer it to users. MySpace has not responded to an inquiry from CNET News.com as to when the temporary solution would be available to users.


It remains unclear how the temporary solution will be distributed. Also, while MySpace had temporarily blocked the web links in question while waiting for Apple's response, MacRumors is unaware of any attempts by the company to address the root cross-scripting vulnerability that may still be potentially be exploited via other yet-unknown means.

Top Rated Comments

(View all)

68 months ago
+1 for Apple's security reputation (which it could use after last month)

-5 for MySpace's security reputation
Rating: 0 Positives / 0 Negatives
68 months ago
well i think it's good that Apple is doing something about it, but myspace shouldn't demand them too though
Rating: 0 Positives / 0 Negatives
68 months ago
Myspace really is a crock. My band's account got compromised the other day, which was irritating.

And why on earth do people put that ridiculous transparency effect on their pages? Crashes Safari every time.
Rating: 0 Positives / 0 Negatives
68 months ago

Myspace really is a crock. My band's account got compromised the other day, which was irritating.

And why on earth do people put that ridiculous transparency effect on their pages? Crashes Safari every time.


Because the people that use them don't know what a good webpage looks like?
Rating: 0 Positives / 0 Negatives
68 months ago
This is potentially much more harmful to Apple from a PR standpoint than last week's Nike+iPod "stalking" story. Let's see what the press does with this one.
Rating: 0 Positives / 0 Negatives
68 months ago
Well, bitching about MySpace aside, there is a vulnerability in Quicktime. Which is bad. But Apple is fixing it, which is good. I can live with that, I guess.
Rating: 0 Positives / 0 Negatives
68 months ago
Isn't Myspace run by a (former) notorious spammer? That says something about their credibility.
Rating: 0 Positives / 0 Negatives
68 months ago
Is it wrong of me to get a good chuckle from this story? ;)
Rating: 0 Positives / 0 Negatives
68 months ago

Is it wrong of me to get a good chuckle from this story? ;)


No actually... :D
Rating: 0 Positives / 0 Negatives
68 months ago

Isn't Myspace run by a (former) notorious spammer? That says something about their credibility.


You mean NewsCorp?

Yeah, Rupert Murdoch has a long history of Nigerian Bank Account schemes...
Rating: 0 Positives / 0 Negatives

[ Read All Comments ]