Style Injection Phishing
Saturday, May 5th, 2007This is certainly not new, but I happened across an interesting link to a bunch of phishing sites built into MySpace. Instead of being a normal phishing site that rely on JavaScript injection or email, the MySpace phishing sites rely only on injecting a form that overlays over the page itself. The URL to find these is a simple Google dork.
At the time of writing there were 56 phishing sites on MySpace. Obviously not huge as a percentage, but it’s scary that there are any at all. It’s unclear what they want to do with these urls, however, I spent a few minutes mapping out the URLs used by the phishers:
- 5 x hur.be
- 4 x willgle.com
- 2 x r3voluti0n.com
- 1 x m3rm.org
- 1 x spaceadder.info
- 1 x coolton.dajoob.com
- 1 x www.profilespider.com
- 1 x www.itfailz.net
- 1 x artexstudios.com
- 1 x members.lycos.co.uk
- 1 x login-myspace.logindotspace.com
- 1 x www.googleidols.com
So only 20 were working/alive as I checked. I was able to find one example of the PHP script used (almost all of them were written in PHP). This one was simply wildly mis-configured. A number of them appeared to be old and were hobbled by MySpace who changed the URL to a “..” which had the effect of breaking the script, but the pages were still messed up (as if MySpace pages aren’t already messed up enough to begin with). Pretty ugly.


