The video is a rigged QuickTime file that exploits a MySpace vulnerability and an alert posted on Friday.in Apple Computer's embedded media player, Web security firm Websense said in
When played by a MySpace user, the video adds itself to the user's MySpace page and replaces the links on the user's profile with links to phishing Web sites, Websense said. Phishing sites are fraudulent sites that attempt to trick people into giving up sensitive information such as log-in credentials.
A MySpace representative on Monday said she could not immediately comment on the worm.
"It seems that we have a MySpace worm on our hands, using a malicious QuickTime MOV file to spread," Mikko Hypponen, chief research officer at security company F-Secure, wrote in a blog posting Saturday.
The same happens when viewing an infected page with Firefox, according to a CNET News.com reader who had his MySpace profile compromised.
The object of the attack appears to get people to visit the phishing Web sites. These pages are crafted to look like MySpace log-in pages and prompt users to enter their MySpace credentials, according to F-Secure.
This is not the first threat to hit MySpace. Miscreants have exploited the popularity of the Web site before toand to . Also, some MySpace users have exploited weaknesses in the site .
Experts have warned that as Web sites are becoming more interactive,. The development momentum for many sites is all about features, with protections being neglected, they have said.
An infected MySpace page will include links to the fraudulent Web sites and a blue navigation bar that is not typically found on MySpace pages, according to researchers at FaceTime Security Labs.
"If this is the case, you will need to clean out your profile and check if any of your friends have also been infected," Chris Boyd, director of malware research at FaceTime, wrote in a blog post.