M.O.M.B.Y! ([info]momby) wrote,
@ 2007-03-15 21:36:00
Previous Entry  Add to memories!  Tell a Friend!  Next Entry
Current mood: energetic
Entry tags:bugs, momby, mypsace, myspace, overflows, whatever, xss

OFFICIAL ANNOUNCEMENT: April 2007 is the Month of Myspace Bugs, Yuss!
April, 2007, will be designated the "Month of Myspace Bugs, Yuss!" Reasons:

  1. Myspace is important, in that there are a bazillion users and a kajillion dollars involved.
  2. "Months of Bugs" are whiny, attention-seeking ploys for acceptance. Myspace's design use is to enable whiny, attention-seeking ploys for acceptance.
  3. "Months of Bugs" are annoying, so rather than suffering through another, we figured it'd be better to just create our own where we could at least direct the content a little.

And now the FAQ.

I have a bug that I told Myspace about but they never fixed it. Want it?

Yes! I mean, Yuss! Send it to mondo_armando@catholic.org and let us know:

  • When you discovered it, if you already told Myspace, and when you did that. If not, then say so, too. If we have to guess, well, fine.
  • If you have a proof of concept (PoC) already put together, tell us how to repro it so we can clearly demo it using a dummy account. If you don't have a PoC, make us believe it works without making us go through a lot of hoops.
  • If you want credit, and if so, to whom, and be explicit. If you want credit to "loser@gmoneyvulns.org" or "G. Money Vulnman" or "gopher://gmoneyvulns.org," or all three, then tell us, and maybe we'll get it right. If we accidentally reveal your superhero identity, well, sorry. Get a new one. We did.

Or, just forget all that and just post it as a comment of http://momby.livejournal.com. Do try to keep the salient info together (when you found it, a link to a reasonable PoC, etc.) This probably means you need a livejournal account, of course.

What Bugs Will We Accept?

While heap overflows and format strings and integer wraps are great and everything, we don't intend to have too many "real" bugs. Most of what we intend to publish are silly XSS/misleading CSS style bugs that Myspace users may actually be able to use for a little while, and that involve only Myspace.com stuff. But in the end, the only requirement is that all bugs posted as part of MOMBY must have an attached PoC that touches Myspace.com, somewhere. So, browser bugs, Flash bugs, QT bugs, all are fine, even though they're third party. Bugs in myspace skinning services or whatever is ideal, especially if most users would blame Myspace for the problem.

And finally, old bugs are fine, if they have a myspace application (and are unpatched). We will almost certainly recycle, should we come up with applicable techniques that involve teh mypsace.

Who's this "We?"

Me: Mondo Armando. Him: Müstaschio. The details of our lives are quite inconsequential.

Is this Gay as Hell?

Yes. But! If it ends up being just as lame as the Month of Apple Bugs, then we haven't really missed the mark. If it's funnier, then great. If it kills this Month of Whatever fad, then hurray for everyone, it's over.

How can I most effectively ignore you?

Add mondo_armando@catholic.org to your favorite anti-spam engine, and add http://momby.livejournal.com/ to your proxy blacklist.

When are you starting?

Were you not paying attention? April 1, 2007. Yes, we know. No, it's serious. No, not really.

What's your press contact info?

E-mail mondo_armando@catholic.org your name and publication, and one of us probably already knows you if you're a tech writer who's been around the block. We will get back to you, usually near the evenings Eastern US time.

Update on press contacts

Our phone/skype situation is dicey, so it looks like IM will be the way to go. Or, if you're not working on a particular deadline, we are open to answering questions, and answering followups, via e-mail. All the quotes you've seen in so far have been generated by these "e-mail interviews."


About our jackbooted censorship policy

Apparently, some people believe it takes several repetitions of "you're a faggot!" and "this is stupid!" to convince us of these valid, though somewhat obvious, points of view. We respectfully disagree. If we/our readers wanted to read dozens of the same go-to-hell comment worded slighly differently, they can go to slashdot and fling their poo there.




Page 1 of 2
<<[1] [2] >>

(Post a new comment)

fun!
(Anonymous)
2007-03-17 07:30 pm UTC (link)
Man you guys are great! Be my friend!

(Reply to this)(Thread)

Re: fun! - [info]7wrc, 2007-05-02 04:14 am UTC

(Anonymous)
2007-03-18 02:37 pm UTC (link)
definitely weird, but oh well. enjoy being smart to computer nerds, evil to the weird little girls that use myspace, and odd to everyone else in the world.

its like what andy warhol said, "everybody deserves 15 minutes of fame" im guessing this is yours...

(Reply to this)


(Anonymous)
2007-03-18 02:39 pm UTC (link)
# "Months of Bugs" are whiny, attention-seeking ploys for acceptance. Myspace's design use is to enable whiny, attention-seeking ploys for acceptance.

nice.


but seriously, why ruin 30 ways of fucking with myspace?


(Reply to this)(Thread)

(no subject) - [info]momby, 2007-03-18 04:22 pm UTC
(no subject) - (Anonymous), 2007-03-18 06:12 pm UTC
(no subject) - [info]keishadyfo, 2007-06-01 04:56 pm UTC
Preparing for the (nearly) inevitable
[info]momby
2007-03-18 05:05 pm UTC (link)
In the increasingly likely event that Six Apart disables this journal, please check my Twitter status page for a new URL: http://twitter.com/mondo_armando

Though pulling the plug here would ruin all the positive anti-Myspace cred 6A is currently enjoying (to the tune of +500 diggs this morning), who knows what goes on in the twisted minds of attorneys.

(Reply to this)

Cheers!
[info]think575
2007-03-18 06:42 pm UTC (link)
A mission, from God....
Cheers guys. Keep up the great work, youre going to make my April something to look forward to. You got dugg too btw. Looks like a lot of people out there are going to be looking for whats coming.

(Reply to this)


(Anonymous)
2007-03-18 09:24 pm UTC (link)
Will this diabolical scheme use social engineering?

As an ignorant myspace user, I would like to preserve some sort of function-- fuck it. Do what you need to. :) best wishes

(Reply to this)

looking forward to it
(Anonymous)
2007-03-18 10:29 pm UTC (link)
i was going to delete my myspace account, but i think i'm going to keep it now just so i can login and see the mayhem =)
gl guys

(Reply to this)

Looking forward
(Anonymous)
2007-03-19 03:37 am UTC (link)
Interesting stuff. Looking forward to hearing what you'll got

---
http://free-wii-nintendo.blogspot.com/

(Reply to this)

FREE IPOD FOR YOU FROM MONTH OF BUGS
(Anonymous)
2007-03-19 11:41 pm UTC (link)
The month of bugs teams bring you a once in a life time oppertunity to obtain an IPOD absolutely free! all you have to do is click on the following five links and add each of them to your top 10 warez tracker....

1. Month of browser bugs
2. Month of apple bugs
3. Month of kernel bugs
4. Month of PHP bugs
5. Month of MySPACE bugs

Then you must send a message to "Samy" on myspace.com (XSS free please!) that says "this shit isnt funny" and your name and address and a PHREE iPHONE will be sent out to you within several days or however long it takes Müstaschio's mother to cash our cheques.
++++++++++++++++++++++++MONTH OF BLOG SPAM++++++++++++++++++++++++++++++++

(Reply to this)(Thread)

Re: FREE IPOD FOR YOU FROM MONTH OF BUGS - [info]momby, 2007-03-20 01:15 am UTC

[info]5minutes
2007-03-20 03:16 am UTC (link)
1) you amuse me
2) only a month of metasploit bugs could make me laugh more
3) nice threads

(Reply to this)

Are Former MySpace employees allowed?
(Anonymous)
2007-03-20 08:18 pm UTC (link)
Well, we know the code so we would be at an advantage...

(Reply to this)(Thread)

Re: Are Former MySpace employees allowed? - [info]momby, 2007-03-20 09:12 pm UTC
what foolishness
(Anonymous)
2007-03-20 10:09 pm UTC (link)
Please ladies the date, can't wait for those well informed tech commentators in the quality press to pick up on this...
all the best with this (may it run and run).
---------------
terramar.co.uk

(Reply to this)

Fantastic!!!!
(Anonymous)
2007-03-21 11:32 pm UTC (link)
Sup, people i myself hate myspace with all my heart and soul and would love to see you go trough with this i myself have deleted 90+ peoples myspaces at my old school using a keylogger to get passwords although i myself dont have a myspace i feel compelled to get one just to see what you guys do!! keep it up

--------HaX-------------

(Reply to this)(Thread)

The End Justifies The Means - (Anonymous), 2007-03-22 08:41 pm UTC
hmmm
(Anonymous)
2007-03-23 03:26 am UTC (link)
good job..but remember once something dies on the internet, something newer and better just takes its place. You used to be able to blue screen a mutherfucker and shut down his whole pc with some pretty code on yahoo chat, kill full rooms and all kinds of fun stuff, ahh the good ol days...
now there are myspace spam hack...boooooring, kid stuff...go get laid.
NeoChick

(Reply to this)


[info]gramercy
2007-03-23 05:50 pm UTC (link)
Score. I'm pretty much as technologically inept as the next myspace assclown, but find this awesometastic anyway.
Even if it's a joke, good job inflicting paranoia.

(Reply to this)

emo kids crying...
(Anonymous)
2007-03-26 01:12 pm UTC (link)
hehe cant wait for all of those emo kids crying at theyre page that looks like poop after they CSS Styles go AWOL hehe pwned emo's!! bring on april...only a few days left guys!!

(Reply to this)

APRIL FOOLS!!!!
(Anonymous)
2007-03-27 05:54 pm UTC (link)
this is just an attempt to pull over an april fools joke on myspace. So they could be known as the guys who pulled one over on that giant.

(Reply to this)

This Bugs Me.
[info]yakmilk
2007-03-28 09:59 am UTC (link)
This bugs me.

(Reply to this)


[info]flamingpig3
2007-04-01 05:47 pm UTC (link)
so, whats the first bug?

(Reply to this)

well??
(Anonymous)
2007-04-02 04:37 am UTC (link)
its april!

(Reply to this)(Thread)

Re: well?? - (Anonymous), 2007-04-02 03:41 pm UTC
Myspace friendblaster rpo - (Anonymous), 2007-04-04 10:59 pm UTC
Myspace friendblaster pro - (Anonymous), 2007-04-04 11:00 pm UTC
i never did like myspace...
(Anonymous)
2007-04-07 01:20 pm UTC (link)
im really glad you guys are doing this. i hated how everyones all "oh myspace!!! its the coolest site ev..." shut up your a queer nerd.

so ya. thanks you guys. i sincerely hope tom gets pissed.

(Reply to this)(Thread)

assholes - (Anonymous), 2007-04-18 03:11 pm UTC

(Reply from suspended user)

[info]jon32000
2007-12-27 08:52 pm UTC (link)
they need to have better people to find out these things they should hire you

Ringer Nation

(Reply to this)

hello
(Anonymous)
2008-02-15 08:43 am UTC (link)
http://airplane-tickets.online-cheap-tickets.info airplane tickets

(Reply to this)

google ads in flash
(Anonymous)
2008-02-23 12:51 pm UTC (link)
Have you seen the new script who show google ads in flash?
that script on http://flashsense.blogspot.com

(Reply to this)


Page 1 of 2
<<[1] [2] >>

Create an Account
Forgot your login?
Login w/ OpenID
English • Español • Deutsch • Русский…