The Mac Observer

Understanding the QuickTime/MySpace Phishing Threat

TMO Talk (0)

Reports of phishing exploits on MySpace Web pages that host QuickTime files have reached a fevered pitch - unfortunately most of those reports are slim on details. The potential threat is real, but understanding what it is can help you avoid accidentally giving up your personal information.

What It Is
The phishing threat on MySpace takes advantage of QuickTimeis ability to automatically play Web page movies and open URLs. These features are used for legitimate purposes all the time, but they can also be used to unknowingly redirect someone to an alternate Web page or run malicious JavaScript code.

In this case, code is being used to trick users into giving up personal information: A phishing scam.

How It Works
Since this threat is being used on the MySpace social networking Web site, you first need to have a MySpace User Profile of your own. If you are logged into MySpace and view a maliciously crafted QuickTime file on someone elseis MySpace page, JavaScript code can be added to your MySpace page that makes changes to your user profile.

The malicious QuickTime file can modify your MySpace page by adding links to fake MySpace pages that collect user names and passwords. The file can also copy to your account without your interaction.

What You Can Do
Avoid playing QuickTime movies and audio files on MySpace profile pages. Disabling QuickTimeis auto-play feature is a good idea, too. Hereis how:

  • Choose Apple menu > System Preferences to launch System Preferences.
  • Select the QuickTime Preferences Pane.

  • Disable QuickTimeis auto-play feature.
  • Click the Browser tab.
  • Uncheck Play movies automatically.

Post A Comment or Log-in. Need an account? Register here.
 

Recent Headlines - Updated February 14th

Mon, 10:30 PM
News - Apple to Live Stream Tim Cook’s Goldman Sachs Speech
8:14 PM
News - Chinese Authorities Seize Apple iPads in Trademark Dispute
6:26 PM
News - Apple Tops Harris Reputation Poll with Record Score
5:33 PM
Mac Geek Gab Podcast - MGG 381: Mac Internet Recovery, HTML on iPad, iDevice Syncing, More!
5:04 PM
Apple Stock Watch - Apple’s Stock Sets New Closing High of $502.60
1:50 PM
News - A Great 3-Minute Video Look at Macworld|iWorld 2012
12:41 PM
Deal Brothers - Mac mini 2.5GHz dual-core Intel Core i5:  $699
11:51 AM
Rumor - Pegatron Forced to Drop Zenbook Due to MacBook Air Similarities
11:00 AM
Apple Stock Watch - Apple’s Stock Breaks $500 Mark For First Time
10:20 AM
News - Apple Announces Foxconn Inspections
9:34 AM
iObserver - AT&T Begins Process Toward Offering Shared Data
9:15 AM
News - Apple Files Motion to Stop Galaxy Nexus Sales in U.S.
 

The Mac Observer Reader Specials

  • TypeStyler 11 is now in the Mac App Store!! -- Special Introductory Price of $59.95!! -- To Buy From The Mac App Store Click Here Now!! Or buy direct from Strider Software.
  • Mac RAM Upgrades: MacBook Pro 16GB kits $475, 8GB Kits for $119.99! iMac 16GB RAM Kits (4x 4GB) for $229.99! Mac Pro Memory 32GB Kit for $399.99, 64GB Kit for $889.99! Mac Hard Drives 2TB Seagate SATA II for $249.99! Click Here!
  • Poker Mac If you're using a Mac, then you've gotta check out Online Poker Mac. This mac poker and online casino mac site actually does the unthinkable, it actually rewards!

Apple Stock Quote (AAPL)

Loading...

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features

Support The Mac Observer

We noticed you may be running AdBlock on your computer. It takes real money to run this site and to deliver the news, tips, and opinions you love to read.

If you wish to block the ads that pay for the creation of our content, we ask that you instead support TMO Directly, either with a $5 monthly recurring contribution, or a one-time donation of any amount of your choice. Thanks!

Subscribe with Paypal Donate with Paypal