Email a copy of "New MySpace Phishing Attack" to a friend.
It begins with a Quicktime file being embedded in a Profile page. If the user "runs" the file (simply visiting the infected page is enough to trigger the attack in most cases), it uses the HREF function to activate some javascript. http://www.apple.com/quicktime/tutorials/hreftracks.html
When this happens, the profile page is "infected" and...