Samy (computer worm)
{{Short description|None}}
Samy (also known as JS.Spacehero) is a cross-site scripting worm (XSS worm) that was designed to propagate across the social networking site MySpace by Samy Kamkar. Within just 20 hours{{cite web|url=https://samy.pl/myspace/tech.html|title=MySpace Worm Explanation|website=Samy.pl|access-date=2015-12-25}} of its October 4, 2005 release, over one million users had run the payload{{cite web|url=http://it.slashdot.org/it/05/10/14/126233.shtml?tid=172&tid=95&tid=220|publisher=Slashdot|title=Cross-Site Scripting Worm Floods MySpace|date=14 October 2005 |access-date=2015-12-25}} making Samy the fastest-spreading virus of all time.{{cite web |url=http://net-security.org/dl/articles/WHXSSThreats.pdf |title=CROSS-SITE SCRIPTING WORMS AND VIRUSES : The Impending Threat and the Best Defense |website=Net-security.org |access-date=2015-12-25 |url-status=dead |archive-url=https://web.archive.org/web/20110104191201/http://net-security.org/dl/articles/WHXSSThreats.pdf |archive-date=2011-01-04 }}
The worm itself was relatively harmless; it carried a payload that would display the string "but most of all, samy is my hero" on a victim's MySpace profile page as well as send Samy a friend request. When a user viewed that profile page, the payload would then be replicated and planted on their own profile page continuing the distribution of the worm. MySpace has since secured its site against the vulnerability.
Samy Kamkar, the author of the worm, was raided by the United States Secret Service and Electronic Crimes Task Force in 2006 for releasing the worm.{{cite web|url=http://lists.owasp.org/pipermail/owasp-losangeles/2008-December/000037.html |title=[Owasp-losangeles] OWASP LA |website=Lists.owasp.org |access-date=2015-12-25}} He entered a plea agreement on January 31, 2007, to a felony charge.{{cite web|publisher=Techspot.com|title=MySpace speaks about Samy Kamkar's sentencing|first=Justin|date=2007-01-31|last=Mann|url=http://www.techspot.com/news/24226-myspace-speaks-about-samy-kamkars-sentencing.html}} The action resulted in Kamkar being sentenced to three years' probation with only one (remotely-monitored) computer and no access to the Internet for life (this provision was later struck off by a judge), 90 days' community service, and $15,000–$100,000,000 in restitution, as well as a 20-year suspended prison sentence, as directly reported by Kamkar himself on "Greatest Moments in Hacking History" by Vice Media's video website, Motherboard.{{Citation|last=Motherboard|title=Greatest Moments in Hacking History: Samy Kamkar Takes Down Myspace|date=2016-06-01|url=https://www.youtube.com/watch?v=DtnuaHl378M |archive-url=https://ghostarchive.org/varchive/youtube/20211221/DtnuaHl378M |archive-date=2021-12-21 |url-status=live|access-date=2016-06-02}}{{cbignore}}
References
{{Reflist}}
External links
- [https://web.archive.org/web/20160601224701/https://video.vice.com/en_us/video/samy-kamkar/56967e5eebd057947f8d0fc5 Motherboard S01E03 Greatest Moments In Hacking History: Samy Kamkar Takes Down Myspace]
- [http://blog.outer-court.com/archive/2005-10-14-n81.html An interview with Samy Kamkar]
- [https://web.archive.org/web/20160301051921/http://samy.pl/popular/tech.html Technical explanation of The MySpace Worm]
- [https://darknetdiaries.com/episode/61/ Darknet Diaries - Samy (Episode 61)]
{{Hacking in the 2000s}}
{{DEFAULTSORT:Samy (Xss)}}