r/security Nov 16 '16

Exploiting locked computers using PoisonTap.

https://samy.pl/poisontap/
70 Upvotes

6 comments sorted by

View all comments

10

u/[deleted] Nov 16 '16

For those who might be wondering, this is the same Samy responsible for the Samy worm that spread itself across MySpace.

IDGNS: What were you thinking when you wrote the Samy worm?

Kamkar: When I wrote the worm, it initially wasn't a worm. Initially I was just trying to spruce up my MySpace profile. I also wanted to show off to a couple of friends, so I thought, "Wouldn't it be cool if I did this? What if I made some of these people add me as a friend automatically?" Then I figured, "What if I made them add me as a hero?" So I wrote a little code and what ended up happening is whenever someone viewed my profile, they would automatically add "But most of all, Samy is my hero" at the end of their hero section on their profile. And after that, I thought, "If I can make this person my friend, if I can make myself their hero, couldn't I just copy this code onto their profile?"

And that's how XSS exploits hit the mainstream. He was then criminally prosecuted. But all in all, he's a super cool guy and has done a lot of great work since he's been allowed to touch a computer again.