Jump to content

Recommended Posts

  • ExTS Admin
Posted

Another clickjacking scam has hit Facebook, tricking hundreds of thousands of users to post messages to their pages saying that they like the malicious link, security firm Sophos said on Tuesday.

 

Like most of these scams, this one relies on social engineering and piques the interest of prospective victims with messages like:

 

• "LOL This girl gets OWNED after a POLICE OFFICER reads her STATUS MESSAGE."

 

• "This man takes a picture of himself EVERYDAY for 8 YEARS!!"

 

• "The Prom Dress That Got This Girl Suspended From School."

 

• "This Girl Has An Interesting Way Of Eating A Banana, Check It Out!"

 

Clicking on the links takes the visitor to what appears to be a blank page with just the message "Click here to continue." However, hidden in the page is code called an iFrame written for Windows-based systems. When a visitor clicks anywhere on the page the iFrame publishes the message to the visitor's Facebook page.

 

"If you believe you may have been hit by this attack, view the recent activity on your news feed and delete entries related to the above links," Sophos' Graham Cluley recommends in his blog post on the attack. "Furthermore, you should view your profile, click on your Info tab and remove any of the pages from your 'Likes and interests' section."

 

There are more technical details behind the attack in this Sophos blog post which dubs the attack "Likejacking."

 

Facebook has been notified and the malicious pages have been suspended, according to BitDefender's Malware City blog.

 

 

Source:

Facebook attack tricks users into 'liking' malicious links | InSecurity Complex - CNET News

Member of:

UNITE

  • Replies 0
  • Created
  • Last Reply

Top Posters In This Topic

Popular Days

Top Posters In This Topic

Popular Days

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...