Home > MySpace Hacker's Profile Deleted After DefCon Demo

News

MySpace Hacker's Profile Deleted After DefCon Demo

9/14/2007

A demonstration by University of Akron student Rick Deacon on ways to hack MySpace accounts backfired when Deacon discovered that his own account was disabled immediately following his presentation at the recent DefCon computer security conference in Las Vegas.

Deacon found a message in his MySpace inbox informing him that his account had been suspended for violation of the site's terms of use. "In retrospect, I should have used a dummy account," he told Agence France-Presse.
 
Deacon demonstrated a technique called cross-site scripting, which involves adding extra information to a trusted Web page in order to mislead a user via a Web browser. By tricking a victim into clicking on a link, Deacon showed that it is possible to capture the Web browser file, or cookie, which automatically logs a user into the site. This can then be used to access their account, Deacon said.

Deacon claimed that he alerted MySpace to the problem some weeks ago but that the site had not responded. Now, however, MySpace has patched the vulnerability.

Bruce Schneier, a computer security expert with BT Counterpane, told AFP that the demonstration highlights a trend in which hackers are trolling social networking sites more frequently. "It's not that MySpace is worse than anything else," he told New Scientist. "It's just that social networking sites are becoming juicier targets."


Paul McCloskey is a contributing editor for the Campus Technology group of publications.

Cite this Site

Paul McCloskey, "MySpace Hacker's Profile Deleted After DefCon Demo," Campus Technology, 9/14/2007, http://www.campustechnology.com/article.aspx?aid=50243

copy text (above) for proper citation



Recommended Reading
  • Sun, Stanford Working To Archive History

    In May in San Francisco, experts from leading universities, libraries, and research institutions around the world met as part of an ongoing effort to address a pressing issue: archiving the world's history, right up to today.

  • The Quilt Coalition Rolls Out XO Communications for High-Capacity Network Services

    The Quilt, a coalition of 28 regional network organizations, has added XO Communications Services to its authorized vendor list. The Quilt represents 200 universities and thousands of other educational institutions across the United States. With this new relationship, Quilt members can purchase XO's high-speed IP transit and network transport services at competitive rates.

  • Wimba Classroom 5.2 Expands Classroom Capture Support, Adds MP3 Downloads

    At the NECC 2008 conference in Texas this week, Wimba launched a new version of Wimba Classroom, the virtual classroom component of the company's Collaboration Suite. The new 5.2 release expands options for classroom capture and adds a variety of other functional and ease of use features.

  • Automation Chimera: Education Is Not Management

    The lure of automating workflow online so human intervention is minimized is continually reinforced in the minds of higher education administrators by examples of automated campus systems such as financials, student information systems, and other enterprise systems. But what's good for management is not always good for learning.

  • Cognos Releases BI Software for Linux-based IBM System z Mainframe

    Cognos, which IBM acquired in January, has released an update to its business intelligence software that will run on the Linux operating system on IBM System z mainframes. IBM Cognos 8 BI was being developed by the two companies prior to the acquisition, but assimilation of Cognos into IBM accelerated development.

  • Facebook and Collegiality: A Serendipitous Social Niche

    Facebook is a way to greet a colleague as if she or he is on your own campus: a wave at a distance, a hello at the corner burrito place, a honk as you both leave the campus parking lot. Informal collegiality has been extended over the miles.