« The Sick Get Sicker | Main | One fifth of human genome patented »

The Sorcerer's Cross-Site Scripting Attack

A clever 19-year-old on a community website, MySpace, figured out a way to take advantage of an Internet Explorer bug so that IE users who viewed his profile would automatically list him as their friend and their hero, and add the code that did this to their own profiles. This is his timeline of the release of his script.

12:34 pm: You have 73 friends.
I decided to release my little popularity program. I’m going to be famous…among my friends.

1 hour later, 1:30 am: You have 73 friends and 1 friend request.
One of my friends’ girlfriend looks at my profile. She’s obviously checking me out. I approve her inadvertent friend request and go to bed grinning.

7 hours later, 8:35 am: You have 74 friends and 221 friend requests.
Woah. I did not expect this much. I’m surprised it even worked.. 200 people have been infected in 8 hours. That means I’ll have 600 new friends added every day. Woah.

1 hour later, 9:30 am: You have 74 friends and 480 friend requests.
Oh wait, it’s exponential, isn’t it. Shit.

I love that part.

Comments

I love that part.

yes indeed. that's hilarious. you can just imagine that "oh shit" feeling...

"I rule. I hope no one sues me."

Also words to live by.

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)