PDA

Click to See Complete Forum and Search --> : Myspace site crashes browser


ric-o
July 12th, 2006, 10:10 PM
I went to the Myspace page that paperghost talks about on his blog posting at Vitalsecurity.org (http://www.vitalsecurity.org/2006/07/here-is-guy-pushing-zango-in-myspace.html) and it starts loading then Mozilla gives a illegal operation and crashes - anyone else have this problem? The Myspace site is here (BE CAREFULL AS IT MAY BE MALICIOUS) (added spaces for safety sakes for the newbs)

h t tp:// www. myspace.com/myspacegraphichelp

I pulled down with WGET the site html and all the graphics files it points to. McAfee and couple other AV scans come up with nothing and so did a alternate data stream scan as well.
I'm running Mozilla version 1.7.13 with Active-X and JAVA turned OFF. I'm not all that worried about my machine as I was running Mozilla inside a sandbox but I'm just curious what its doing.

Any thoughts? Puzzled.

brokencrow
July 12th, 2006, 10:27 PM
One of my users came to me with the same issue today. His buddy's MySpace site crashes Firefox but is OK in IE. You're not alone...

edit -- page looks OK in Opera 8.54

edit #2 -- surfing around myspace from that page did end up crashing Opera. Rebooted to Ubuntu, so far, so good w/ Firefox on this OS.

ric-o
July 12th, 2006, 11:12 PM
Thanks bc. Yeah, it works fine in IE for me too.

I guess I just got freaked out because I JUST read about some folks finding images with exploits in them on some websites....dont have a reference link to this but will hunt around where I saw that.

brokencrow
July 12th, 2006, 11:26 PM
I never checked it with IE (my user did though). I wouldn't go surfin' some of these sites with IE to save my life...

shadowroot
July 13th, 2006, 11:17 AM
I some times use a local library to do some surfing for mics. reasons. The network admin is really... busy i guess because from the looks of the machines, they were setup a few years ago and never updated. Some times the IE browser crashes when i look at certain myspace pages. I suspect it's all that java script. It has the same problem on a few other javascript loaded pages. I normally get a flash of most of the page so i try to hit 'stop' and catch the buttons i need to nav.

nihil
July 13th, 2006, 12:00 PM
Hmmmm,

I used Firefox and couldn't replicate the problem.

I have just updated all my Java though, because I was messing with something else............ might that be the answer?

.:front2back:.
July 13th, 2006, 01:05 PM
hmmm it's seems that they are using a similar exploit that was crashing the opera browser a few weeks back..

very very sneaky indeed.. :(

brokencrow
July 13th, 2006, 01:39 PM
I suspect it's all that java script. It has the same problem on a few other javascript loaded pages.

Come to think of it, this site locks up Firefox on an old PII I still run, and I suspect it's all that java script coded in here.

ric-o
July 13th, 2006, 03:19 PM
Originally posted here (http://www.AntiOnline.com/showthread.php?threadid=275938#post907709) by .:front2back:.
hmmm it's seems that they are using a similar exploit that was crashing the opera browser a few weeks back..
f2b: Did you figure out what the code is doing that?

bc: Yeah, I never use IE to surf unknown sites - Mozilla with JAVA and scripting off AND inside of SandboxIE (http://www.sandboxie.com) and throw the sandbox away at end of surfing session.

hexadecimal
July 13th, 2006, 03:53 PM
killed camino afew times.
mozilla 'safari' like browser for osx

when i made my myspace i used a code generator to make my layout. i wonder if some of these generators are spitting out sub-par code and is causing the problem.

ric-o
July 16th, 2006, 09:28 PM
FYI, just to close the loop on this item...

Looks like this page was an employee of Zango (see Vitalsecurity.org's story (http://www.vitalsecurity.org/2006/07/techdirt-securitypronews-coverage-of.html). Guess a bunch of MySpace sites were propagating the spyware (Zango)...tsk tsk tsk.

As of July 14 MySpace those sites were either shutdown or Zango software removed - see Vitalsecurity.org post here (http://www.vitalsecurity.org/2006/07/vm-day-victory-in-myspace.html)

My suspects this wont be the last time we see an online social networking site being used to spread spyware crap. :mad:

giggles859
August 14th, 2006, 05:54 AM
i got a good question on this topic ... every browser i use ... wether(sp) it's firefox,opera,IE,firefox tux, nautilus, konquerer, mozilla, etc.
it always crashes viewing my profile on myspace .. it confuses me cause it's not just a firefox thing ... it's a whole OS thing... windows and linux.... havent tried mac yet ....
now i'm not tryin to spam my stupid little blog .. but i'm looking for some input on what could be the cause
http://www.myspace.com/vernwolf
dont have other tabs open when ya click it .. it may crash whatever you're using

acidtone
August 14th, 2006, 06:02 AM
Nope no crashing on my end, left my other tabs open and it loaded fine for me..

Although there was a small spike in the CPU usage, but other then that nothing out of the normal.

cheers
acidtone..:)

giggles859
August 16th, 2006, 07:39 AM
*scratches head*
any other ideas?
*edit* for crazy idea
maybe that cpu spike is a system call that i havent been able to chase down yet possibly something sound related? cause the only thing i can think of that's odd w/ my system is the corrupt audigy eeprom ... but i cant see why that would only crash the browser and not take the whole system down with it

giggles859
August 18th, 2006, 07:54 AM
javascript malformation.

someone farked up their js and it's killing all my browsers.
pull the js and no crash