posted here so I can delete the post should I choose… unlike a digg comment
http://rapidshare.com/files/11165822/first_part_of_one_style_of_embed_exploit.txt
uses document write to load a quicktime movie with embeded js. appends that code to the end of the logged in user’s profile, adds some credit text, and tries to add a given profile as a friend (for attention).