MySpace


LoLo

Loren Williams


Last Updated: 6/24/2009

Send Message
Instant Message
Email to a Friend
Subscribe

Gender: Male
Status: Engaged
Age: 29
Sign: Aquarius

City: New Orleans
State: Louisiana
Country: US
Signup Date: 10/5/2005
Saturday, December 02, 2006 

Category: MySpace
Yesterday, a metric ton of MySpace accounts were infected with yet another worm. As I predicted ten days ago, it was accomplished via a QuickTime embed. Visiting the profile of anyone infected would cause the navigation links across the top of your profile (Home   |  Browse  |  Search   |  Invite   |   etc...) to be replaced by fake navigation links which all linked to a spoof MySpace login page via some basic CSS and HTML added to your "About Me" section. And, the QuickTime embed was added to one of your "Interests" sections to further propagate this worm / phishing attack. At a glance, this looked like nothing more than that: a worm being used to phish MySpace passwords.

I downloaded the .mov (QuickTime File) and opened it up in a text editor to see what it was triggering to cause this mess. It was plainly clear that the JavaScript it was executing; from the same domain as the spoof login page, was intended to do more than just inject some code to phish people and spread the worm. It also had code in there to send internal MySpace messages to random people with MySpace friend IDs between 105000000 and 80000000. This attempt fell flat, but the intent was there nonetheless. Why did it fail? Either poor coding or MySpace's spam filter. This ill-fated spam attempt revealed the identity of the guy behind the worm... Well, it made it so that he won't be all that hard to track down anyway.

The intended MySpace message spam would have randomly used one of the following subject lines:

what else is there to do on a Sunday.?.......
You better not forget about this..
Hehe that was so funny..
better see this one last time lol..
omg did you see this last nite..
whos coming to the party tonight.?..

And, the body of the message would have contained a fake YouTube video (pictured below) linked to a site that's.... Pushing Zango installs (nasty adware).

Fake YouTube Porn

If you're not already familiar with Zango (180solutions) and their scumtastic business practices, read this. The bottom of that write-up has links to a bunch of stories detailing their unrelenting scumbaggery. It's no wonder that the FTC spanked three million dollars out of those idiots recently.

*The web addresses listed in the below paragraph contain adult content*
The url that Fake YouTube video would have been linked to is what gave this douche-bag up: http://google.com/url?q=http://www.vidchicks.com/home.php. That "home.php" simply redirects you to the same url you'd get as a pop-under if you visited any page on Vidchicks.com: http://www.vidchicks.com/popunder.html. And, that popunder.html is simply a landing page being used to get people to install some adware courtesy of Zango. I was able to dig up all kinds of dirt on the webmaster of Vidchicks.com. I'll get to that in a second.

On the landing page he's pushing the Zango installs from, he has visitor tracking being logged by the public version of Extremetracking.com. If you're reading this before they pull his account, those stats can be found here. The visitor stats found there are pretty telling. He has been spamming the hell out of MySpace from those phished accounts via messages, comments, and bulletins.

The below shows unique visits:
MySpace Spammer's Stats

Visiting a few of the MySpace profiles he has gotten visitors from recently showed that he has been posting various images as comments from phished accounts to get people to visit that Zango landing page of his. Sometimes he simply posts the same fake YouTube video as above. Other times, he'll post stuff like the below:

MySpace Comment Spam

So, he's basically just scumming it up in any way that he can. After doing a bit of research on this guy I found that this is his typical behavior.

Here's a taste of the pile of dirt I found on this guy:

1. He goes by a number of different names on webmaster forums because he has a knack for doing shady stuff. If you're doing business with a guy that goes by the name eLogic or Creepah, I highly suggest that you stop. Those are two of his handles for sure. The eLogic name is used on some forums where he does traffic trades and whatnot. And, he tried to sell Vidchicks.com on DNForum (registration required, DNForum sucks like that) a few weeks back under the name Creepah. Oh yeah, Vidchicks.com is registered under the fake business name of eLogic Inc.

2. He was banned from a webmaster forum for creating a fake account to bid on one of his own auctions to drive the price of a site up. *No url included because it's a private forum

3. He was apparently banned from YPN at least once.

4. This has got to be my favorite post by this idiot: [EASY CASH] Digg my site, $1 per digg, takes 30secs. lolz

Here's a screenshot from his Digg.com account:
Digg.com Spam
14 stories Dugg and 20 submitted. *Holds up a Yes, this guy is retarded sign*

5. Who cares? I think all of the above establishes this guy as a typical spammer.

In conclusion:
- MySpace killed off that worm yesterday by adding the domains he was using to their spam filter's list and getting the hosts to pull those files. This is just a temp fix though. They'll need to ban QuickTime files if they want to prevent this kind of stuff from happening on a daily basis.

- The guy behind this is obviously in blatant violation of numerous laws. If any law enforcement or other government agency wants to take action against this idiot: it'll be real easy to nail him down. On all the webmaster forums, he has remained consistent in saying that he's from the UK. This isn't necessarily true, but a subpoena served on any of his income sources (Zango, Adult AdWorld, etc) would turn up a address for sure. ;-)

- I've got the flu and didn't sleep last night, so excuse any typos and/or other retardedness in the above.

* The above is a repost from my Ghettowebmaster.com site.
** If you're a member of Digg.com, Digg this story and me luv you long time.
*** To subscribe to this blog: Click Here
**** Asterisks are fun
_______

Update (12/01/06):

"MySpace killed off that worm yesterday by adding the domains he was using to their spam filter's list and getting the hosts to pull those files. This is just a temp fix though. They'll need to ban QuickTime files if they want to prevent this kind of stuff from happening on a daily basis."

Well, MySpace has apparently decided to try to handle this issue differently. And, the same worm is spreading around today using different domains to host the QuickTime file, Spoof Login page, and JavaScript. I guesstimate that at least 1/10th of all active users were infected by this thing over the past few days. And, there is no telling how many accounts have been phished. Yesterday, MySpace Tom posted the below:

MySpace Tom's Phishing Blog

I think that makes it pretty safe to say that the MySpace crew has come to the same conclusion as me: a metric TON of people have already been phished via this worm setup. I smell a lot of spam in the near future.

Yesterday, I didn't mention a part of this guy's hustle that is pretty interesting. He is hosting the files being used for this worm on domains he has compromised. I imagine he is doing this in order to have a little room for denial. "Dude, I don't know what you guys are talking about. Someone else is spamming the hell out of that place with the url to my Zango page." Yeah, sure.

As of right now:
He cleaned up his JavaScript a bit and it now randomly inserts the QuickTime file from one of two domains. Yesterday he was using two domains also, but they were both standalone operations doing the exact same thing. So, he has the QuickTime file, JavaScript, and spoof login page sitting on two separate domains - working together now. His phishing efforts have been cut short though. Both of the Spoof Login pages are set to post the inserted data over to a third domain (a .edu) which is already down. And, the webmaster at one of the domains added some text to the spoof login on his domain warning people that it's a fake:

MySpace Spoof Login

I'm not sure if he has this same double-whammy setup on any other domains right now though. If not, I'm sure he will soon enough. I'll say it again: this is not going away until MySpace bans QuickTime embeds.

P.S. If you want to block this thing from screwing with your profile you can add .mov to your blocked extensions if you have FireFox and Adblock. If anyone wants to write a blog explaining this to newbies, I'll gladly link to it from here. Thanks for the idea Abraxus. ;-)

Tiny Update:
If you want to protect yourself from getting / spreading this worm and other stuff that is sure to follow:

1. Download FireFox to use as your internet browser. Sorry Billy G :P
2. Follow the instructions in this forum post on how to add Adblock and the settings to block QuickTime files from screwing with you.

There are other ways of blocking this, but that's a pretty easy one.

Another Tiny Update:
Here's a nifty  blog entry (with videos) that takes you through the process of installing Adblock in order to protect yourself from this worm: AdBlock Plus Tutorial

Listing 1-50 of 168
1234
of
4
Chillin'

 
my hereo ....LoLo.. hehe
 
Posted by Chillin' on Thursday, November 30, 2006 - 5:53 PM
[Reply to this
PETER IASILLO ~ NYACTOR
Peter Iasillo, Jr.

 
NICE WORK MY FRIEND!!

I also posted INSTRUCTIONS ON HOW TO REMOVE THE FAKE NAV BAR CODE in a Bulletin. If anyone reading this is a Myspace friend of mine go there and read the instructions.

Please allow me to repost the bulletin here for the benefit of anyone not in my circle of friends? THANK YOU! ~ Peter Iasillo

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

It is EXTREMELY IMPORTANT that you read this whether you have the fake nav bar or not. Take a few minutes to save yourself hours.

If you are clicking on your MENU NAVIGATION BAR and it is going nowhere, you NEED to perform a search in your ABOUT ME Section because you have the epidemic phony NAV BAR CODE.

Here is what I posted EARLY this morning:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I am working with my friend Brian who discovered the offending code while looking at the source code for my page.

As you should all know there is a phising epidemic on Myspace that somehow puts a phoney Menu Bar across the top of your profile and covers your actual menu bar.

I found the code at the bottom of my ABOUT ME section.

Use the FIND command or CTRL F to find the word LOGIN.

It starts with this line of code ... I have stripped out the first "<" bracket and the last "}" here:

style type="text/css"
div table td font { display: none }
div div table tr td a.navbar, div div table tr td font { display: none }
.testnav { position:absolute; top: 136px; left:50%; _top: 146px

The code was at the very end/bottom of my ABOUT ME section.

It then continues with an obvious line of code for the menu choices. I stripped out the code and the page is fine ... FOR NOW!

F*CKING TOM!!

Thanks Brian ... Myspace should give YOU a medal!

Peter

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOW READ THIS AS WELL! EQUALLY AS IMPORTANT. Sorry folks!

Just updated my blog entry about that worm that is replacing the navigation links at the top of profiles with links to spoof login pages. This guy is on a roll.

Here's the blog entry:

http://blog.myspace.com/index.cfm?fuseaction=blog.view&friendID=31797452&blogID=199738585
 
Posted by PETER IASILLO ~ NYACTOR on Saturday, December 02, 2006 - 3:50 PM
[Reply to this
LoLo
Loren Williams

 
P.S. To remove this crap delete the code that was added to the bottom of your "About Me" section. There's a lot of it in there. Then, delete a snippet of code from one of your "Interests" sections. It'll have "piAF2iuswo.mov" in it. ;-)
 
Posted by LoLo on Thursday, November 30, 2006 - 5:57 PM
[Reply to this
Philo-sophia

 
http://profile.myspace.com/index.cfm?fuseaction=user.viewprofile&friendID=114607698

I think he may have put something on that profile or one of his friends there. My firefox got slow and then the script with some david name came up in the address. I should have copied it at the time. But anyhow......nice guy he is. :(((((((((
 
Posted by Philo-sophia on Saturday, December 02, 2006 - 3:58 AM
[Reply to this
Philo-sophia

 
FOUND IT on another profile!!!!!

http://www.daviddraftsystem.com/images/login.html


I got it after leaving a comment on this profile:

http://profile.myspace.com/index.cfm?fuseaction=user.viewprofile&friendID=64711279
 
Posted by Philo-sophia on Saturday, December 02, 2006 - 4:08 AM
[Reply to this
Mrs. Susie Q.
Susie Baranowski

 
Asterisks ARE fun! Thanks for the info. :)
 
Posted by Mrs. Susie Q. on Thursday, November 30, 2006 - 5:57 PM
[Reply to this


 
flu or not GREAT piece of work, hats off my good man!!! Woo! ;)
 
Posted by on Thursday, November 30, 2006 - 5:58 PM
[Reply to this
Bill Mc.
Bill McCormick

 
Yeah, I finally caught on to one before you posted. I feel much smarter now. Thanks for the update.
 
Posted by Bill Mc. on Thursday, November 30, 2006 - 5:58 PM
[Reply to this
Amanda is an AE

 
Way to save us again from nasty cyber crap
Way to go Cyberman :D
 
Posted by Amanda is an AE on Thursday, November 30, 2006 - 6:01 PM
[Reply to this
michele leigh

 
you're the man.
thanks for helping me get that crap off of my profile last night.
i'm spreading the word.
i hope you get to feeling better!
XO
 
Posted by michele leigh on Thursday, November 30, 2006 - 6:04 PM
[Reply to this


 
I hope you get to feeling better!! Thanks so much for your info. It's a great blog!
 
Posted by on Thursday, November 30, 2006 - 6:06 PM
[Reply to this
The Anti-Girl

 
Dear Lolo,
You are awesome.
Will you marry me?
Love always,
me.
 
Posted by The Anti-Girl on Thursday, November 30, 2006 - 6:06 PM
[Reply to this
LoLo
Loren Williams

 
"Will you marry me?"

Score! My first marriage proposal via blog comment.

/I think so anyway. :P
 
Posted by LoLo on Thursday, November 30, 2006 - 6:57 PM
[Reply to this
Ningina

 
But... I was supposed to be your future ex-wife and baby's mama. :-/

Now we must get married so I can file for divorce, on the grounds of your eCheating on me...


/LOLz @ "Asterisks are fun" :-P
 
Posted by Ningina on Thursday, November 30, 2006 - 8:53 PM
[Reply to this
LoLo
Loren Williams

 
You are my future ex-wife.

/well, one of them. :P
 
Posted by LoLo on Thursday, November 30, 2006 - 9:04 PM
[Reply to this


 
Since the second one was more of a prediction than a proposal....will you marry me?? It's legal here in Mass. (for now anyway) And don't hit me with that age difference thing.

I'm second!

Seriously, 2 Kudos for you either way.
 
Posted by on Friday, December 01, 2006 - 5:34 AM
[Reply to this
LoLo
Loren Williams

 
Double Score!!!

A marriage proposal followed up by a gay marriage proposal.
 
Posted by LoLo on Saturday, December 02, 2006 - 8:47 AM
[Reply to this
Ningina

 
I "predict" a throwdown. ;-)
 
Posted by Ningina on Friday, December 01, 2006 - 9:59 AM
[Reply to this
DaveFromColorado

 
All Y'All best be backin' off, yo! I've known him longest! LOLz

--Dave.
 
Posted by DaveFromColorado on Sunday, December 03, 2006 - 4:42 AM
[Reply to this
Ningina

 
Maybe so. Though, I do believe the dress would look just a little better on me. LOLz

/That bitch is mine. Deal with it. ;-)
 
Posted by Ningina on Sunday, December 03, 2006 - 6:48 AM
[Reply to this
DaveFromColorado 

 
there is some good information in this blog, but somehow, reading these comments, I feel so unloved.
 
Posted by DaveFromColorado  on Sunday, December 03, 2006 - 6:55 AM
[Reply to this
The Irish Bastard: Jonny Danger
Jonny Danger

 
How can we ever thank you LoLo?

I order any virgin women reading this to offer themselves to LoLo for this incredible altruistic gesture. It's the least we can do.
 
Posted by The Irish Bastard: Jonny Danger on Thursday, November 30, 2006 - 6:07 PM
[Reply to this
LoLo
Loren Williams

 
I second that motion, but have to add "smoking hot or cute". ;-)
 
Posted by LoLo on Thursday, November 30, 2006 - 6:59 PM
[Reply to this
$★R★#

 
Hey Lolo, Thanks for the info.. that guy is such a douche. I hope you get better soon!! :)
 
Posted by $★R★# on Thursday, November 30, 2006 - 6:15 PM
[Reply to this


 
Great job!!!!!!!!!!!!!!
 
Posted by on Thursday, November 30, 2006 - 6:16 PM
[Reply to this
She's laced up in your shoe.

 
Thanks for the info! On a side note: Are the bullentins that prompt you to upgrade to a 9.0 flash legit?


Hope you feel better soon!
 
Posted by She's laced up in your shoe. on Thursday, November 30, 2006 - 6:18 PM
[Reply to this
LoLo
Loren Williams

 
hmmmm.... That depends. An asshat could setup a little hustle to trick people into thinking that they are download a Flash update when it's really just a virus/adware/etc. Haven't seen any of that going on though. As long as you can view MySpace videos, you don't need to upgrade anything because you already have Flash 9. ;-)
 
Posted by LoLo on Thursday, November 30, 2006 - 7:02 PM
[Reply to this
She's laced up in your shoe.

 
Thanks! I get a lot of bullitens that look legit but ask for an upgrade and I never click on it.
 
Posted by She's laced up in your shoe. on Monday, December 04, 2006 - 3:13 PM
[Reply to this
♥Blonde Trish the Irish Dish♥

 
In like 10 years will you run for president?? For seriously, you would be awesome.

I hope you feel better.
 
Posted by ♥Blonde Trish the Irish Dish♥ on Thursday, November 30, 2006 - 6:28 PM
[Reply to this
LoLo
Loren Williams

 
I'm not eligible for a nomination. :-(

/Damn felonies. lolz
 
Posted by LoLo on Thursday, November 30, 2006 - 7:04 PM
[Reply to this


 
Yeah, wih politics you're supposed ot wait until your already in office to commit them.
 
Posted by on Wednesday, December 06, 2006 - 4:58 AM
[Reply to this
I drive the Chameleon Prius
Donna VanSchaik

 
LoLo, I am sorry to hear that you are sick. Not Fun. I think I got one of those. I blocked them. I do have a question, that perhaps too much pre-birthday celebration didn't allow me to see an answer to was, if I was infected by what I viewed, how would I know I was infected? Should I just automatically go into my interested and look for the piAF2iusuo.mov? I don't want to log out just yet and then log in and get a mess. I replied this way just in case someone else has the same question.

My question referred to this part of your blog:<<SNIP>>Visiting the profile of anyone infected would cause the navigation links across the top of your profile (Home | Browse | Search | Invite | etc...) to be replaced by fake navigation links which all linked to a spoof MySpace login page via some basic CSS and HTML added to your "About Me" section. And, the QuickTime embed was added to one of your "Interests" sections to further propagate this worm / phishing attack.<<SNIP>>

Thanks much Get better dude.
 
Posted by I drive the Chameleon Prius on Thursday, November 30, 2006 - 6:30 PM
[Reply to this
LoLo
Loren Williams

 
Short answer:
I just looked at your profile and you're not infected. ;-)

Longer answer:
If you were infected all the links at the top of your profile (Home | Browse | Search | Invite | etc...) would be linked to either a spoof login page or they'd be broken links.
 
Posted by LoLo on Thursday, November 30, 2006 - 7:06 PM
[Reply to this
™Steve
Steve Garrett

 
good lookin out homie! see...we feel safe in knowing that there are super geniuses watchin our backs! haha...keep your eyes peeled!
 
Posted by ™Steve on Thursday, November 30, 2006 - 6:31 PM
[Reply to this
.

 
you never cease to amaze me.
 
Posted by . on Thursday, November 30, 2006 - 6:32 PM
[Reply to this
Anton Webern: Quite Good

 
Interesting....looks like a combo of the ".." movies from a while ago mixed in with the HREF Track tactic. I wonder if this is the same guy who was behnd these ones:

http://www.vitalsecurity.org/2006/11/zango-and-fake-..-movies.html

I'll try and provide support from Vital and SPG later tonight or first thing tomorrow. Great writeup - I think I have some contacts on those forums so I'll see what else I can dig up ;)
 
Posted by Anton Webern: Quite Good on Thursday, November 30, 2006 - 6:38 PM
[Reply to this
LoLo
Loren Williams

 
There's that damn MySpace spam filter screwing things up again. I really wish someone would sit the MySpace crew down and explain that the only way to fight these shit muffins is to make headlines for going after them.

Yeah, it's a worm/phishing/multi-spamming/fake-youtube/all-roads-lead-to-Zango combo. I've got that same entry of yours plugged in the original of this blog on GhettoWebmaster. When I moved it over here I got the "....." treatment on that link.

/Sweetness. I've got a funny update coming on that CPAEmpire issue too. Those dumbasses finally wrote me back. hehe
 
Posted by LoLo on Thursday, November 30, 2006 - 7:12 PM
[Reply to this
EcoPSYCHOlogist
Stephanie v.n.S

 
OMGosh, I noticed it (last night) on my other profile immediately. I know what my codes look like and knew there was something funny going on.


Thank goodness, I removed them just to be safe. (Note I always check my codes sometime after I log in. I have too. Better safe than sorry)

I've also saved a copy of each section just to refer to. (Saves a lot time) All I have to do is remove each section and replace, if I suspect any funny business! (My method saves me time and headaches)



Thanks for informing... ttyl
HuGs..Stephanie
 
Posted by EcoPSYCHOlogist on Thursday, November 30, 2006 - 6:42 PM
[Reply to this
Cool Nana Lesley
Lesley Dewar

 
Stephanie

That's a great tip. Thanks. I caught some bastard software trying to install itself after I viewed someones profile and they had a special cursor that just displayed as a haircross like a rifle sight.

Hate those things. I like to see what I am playing with - you can leave your hat on (and the light!)

I also hate profiles with black and very dark backgrounds. You have no idea what is lurking there!

Thanks again.
 
Posted by Cool Nana Lesley on Saturday, December 02, 2006 - 8:43 AM
[Reply to this
Greg Foss
Gregory Foss

 
I'm gonna look into Firefox, but just want to throw this in.

With Opera, I click 2 buttons and I have black text on a white background, and no pictures are allowed to cover text. Those impossible to report 'myspace viewer' pages become easy to view and report that way. Makes the mouse look normal as well.

Also useful is Ctrl-F11 which limits the page to the width of my computer screen. No more scrolling right and left.

Great story, I'll keep seeking them out and reporting them, and I really appreciate the time, knowledge and experience you guys put into keeping MySpace a safe space
 
Posted by Greg Foss on Saturday, December 02, 2006 - 3:06 PM
[Reply to this
What would jesus do... with a shotgun?

 
yet again, lolo saves the interbutt from assholes

and as for the html code that screws shit up, perhaps of someone were to have some source for this code so people know what theyre removing?

alot of people just add the codes from whatever generator and might break their profiles trying to remove the code, lol
 
Posted by What would jesus do... with a shotgun? on Thursday, November 30, 2006 - 7:06 PM
[Reply to this
Citizen K

 
WE LOVE YA MUAH!!!!
 
Posted by Citizen K on Thursday, November 30, 2006 - 7:11 PM
[Reply to this
JCro
Justin Crochet

 
graci for the info...we should party one night
 
Posted by JCro on Thursday, November 30, 2006 - 7:34 PM
[Reply to this
Tybalt X
Gabriel Anthony Garza

 
you've done it again, lolo. you are truly the most useful friend to have on Myspace.
 
Posted by Tybalt X on Thursday, November 30, 2006 - 7:43 PM
[Reply to this


 
Thanks a whole bunch, friend! You're my no.1 man!

Get well soon!

♥ Keld
 
Posted by on Thursday, November 30, 2006 - 7:45 PM
[Reply to this
Apple Something

 
So informative. Thank you.
 
Posted by Apple Something on Thursday, November 30, 2006 - 7:52 PM
[Reply to this
Mike

 
Thanks again for this stuff
 
Posted by Mike on Thursday, November 30, 2006 - 8:02 PM
[Reply to this
new champ randy orton

 
what does "Phishing" me
 
Posted by new champ randy orton on Saturday, December 02, 2006 - 9:20 PM
[Reply to this
Ningina

 
Wikipedia's definition of "phishing" --

"In computing, "phishing" is a criminal activity using social engineering techniques. Phishers attempt to fraudulently acquire sensitive information, such as passwords and credit card details, by masquerading as a trustworthy person or business in an electronic communication... Attempts to deal with the growing number of reported phishing incidents include legislation, user training, and technical measures.

... The term "phishing" is a variant of "fishing", probably influenced by "phreaking", and alludes to the use of increasingly sophisticated lures to "fish" for users' financial information and passwords. The word may also be linked to leetspeak, in which ph is a common substitution for f. The popular theory that it is a portmanteau of password harvesting is an example of folk etymology."
 
Posted by Ningina on Tuesday, December 05, 2006 - 5:48 AM
[Reply to this
LoLo
Loren Williams

 
"Phishing with a worm!!!"

I didn't even think of that. If I had, it would have been the blog's title.
 
Posted by LoLo on Thursday, November 30, 2006 - 8:08 PM
[Reply to this
Listing 1-50 of 168
1234
of
4