On CBS MoneyWatch: 11 Buzzwords That Should Be Banned
BNET Business Network:
BNET
TechRepublic
ZDNet

By Elinor Mills CNET News
Posted on ZDNet News: Aug 20, 2009 5:30:09 AM

Update: Facebook on Thursday said it has disabled a group of rogue apps that were stealing Facebook user log-in credentials and spamming people.

"We have disabled all of the apps in question that violated Facebook Platform policies," a company representative said in an e-mail.

The apps were discovered earlier this week by Trend Micro researcher Rik Ferguson, who detailed the problems in a blog post.

Here's the original story:

Security firm Trend Micro warned on Wednesday that a handful of rogue Facebook apps are stealing login credentials and spamming victims' friends.

So far, six malicious applications have been identified: "Stream", "Posts", "Your Photos", "Birthday Invitations", "Inbox (1)," "Inbox (2)" according to a blog post by Trend Micro researcher Rik Ferguson.

As of Wednesday afternoon, all of the apps were live except for "Stream", he said in an e-mail.

The activity started earlier in the week with a Facebook notification Ferguson says he got from an app called "sex sex sex and more sex!!!", which has more than 287,000 fans. The notification said that someone had commented on one of his posts. That app doesn't appear to be malicious and may have been compromised somehow to begin the distribution of the spam, he said.

That first notification included hyperlinks that led to a phishing site on the "fucabook.com" domain, allegedly registered to someone in Armenia, he said. Once Ferguson gave up his credentials (for a Facebook account he uses for research purposes) he was directed to Facebook and to an application install screen for the app called "Posts".

He installed that app and immediately his friends were spammed with a bogus notification "Profile_name has sent you a message", with the hyperlink to the phishing site.

On Tuesday, the first couple of apps were sending notifications that hyperlinked to the fucabook phishing site but by Wednesday the destination had changed to a simple IP address rather than a domain name, he said. A JavaScript that pulls up Facebook bounces the browser around among any of the six rogue apps to get them widely installed and the cycle continues, he said.

All the apps look and act exactly the same and include ads.

"I am keeping Facebook informed of these developments as they arise and they are working hard to rectify the situation," Ferguson wrote on his blog.

A Facebook spokeswoman said the company was looking into the matter and would provide more comment later.

Ferguson recommends that Internet users always check the URL displayed in the browser address bar before entering any sensitive information on a site and hover the mouse over a hyperlink to see the URL. Facebook users should also review their privacy settings regularly and delete any applications they no longer use, he said.


This screenshot shows evidence of the phishing scam on Facebook.
Credit: Trend Micro

This article was originally posted on CNET News.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 16 Talkback(s)
RE: Rogue Facebook apps steal log-in data, send spam
I think sites like this are better for spreading viruses and malware than they are for spreading friendship.I've had to reinstall my daughter's operating system twice...once because of a myspace virus and once because of a facebook virus.she no longer uses either.... (Read the rest)
Posted by: htrabbit Posted on: 08/23/09 You are currently: a Guest | | Terms of Use
Facebook apps  a.barry@... | 08/20/09
RE: Rogue Facebook apps steal log-in data, send spam  Steven J. Ackerman | 08/20/09
RE: Rogue Facebook apps steal log-in data, send spam  mgil@... | 08/20/09
RE: Rogue Facebook apps steal log-in data, send spam  ed3602us@... | 08/20/09
RE: Rogue Facebook apps steal log-in data, send spam  dtroyerSMU | 08/20/09
RE: Rogue Facebook apps steal log-in data, send spam  bondservant4jesuschrist | 08/20/09
It's easy...  Mihi Nomen Est | 08/20/09
How is this any different....  Mihi Nomen Est | 08/20/09
uh-huh, except that...  sir_cheats_alot@... | 08/20/09
All these social networking sites will fade away eventually....  drdoug99@... | 08/20/09
Why...  fog_za | 08/20/09
RE: Rogue Facebook apps steal log-in data, send spam  maspinam | 08/20/09
RE: Rogue Facebook apps steal log-in data, send spam  Computer_User_1024 | 08/20/09
RE: Rogue Facebook apps steal log-in data, send spam  psauve | 08/21/09
RE: Rogue Facebook apps steal log-in data, send spam  guiri | 08/21/09
RE: Rogue Facebook apps steal log-in data, send spam  htrabbit | 08/23/09

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here