I think most of you would have read this news by now. For those who have not, here it is:
A 19 year old geek has used a worm with JavaScript, modified using XMLHTTP Request (within AJAX Web applications) to insert a code into the profiles of people who are visiting his page on MySpace and has gained tremendous popularity, overnight. Particularly this line "Upon executing the code, it would add me as one of their friends. This normally requires their approval, but this was all done in the background via Ajax." in his email interview by Philipp Lenssen is very threatening. You can find the explanation of his code here; very interesting to see how he has hacked his way in.
He has become so popular that Zazzle is selling T-shirts titled "Samy is My Hero"
While we have a very positive outlook towards Web 2.0 and likes, these kind of incidents reminds us that we should not miss out on the security threats that new technologies like AJAX posses.
Related readings :
The Web 2.0 MySpace Friend-Generating Worm
Samy. Their Hero
How to Make 1 Million Friends on MySpace
Hacker Makes Himself the Most Popular Person On MySpace
fast.info