Facebook 'likejacking' attacks continue with flesh appeal
Network World - Facebook users are falling for yet another clickjacking scam that fools them into "liking" a page. This one lure victims with the message "Paramore n-a-k-ed photo leaked," which claims to point to a Web site containing a naked photo of Hayley Williams, lead singer in the rock band Paramore.
But clicking onward only brings the Facebook user to a page which, unbeknownst to the victim, has hidden code that executes the action of "liking" the Web page. That action gets published on the victim's Facebook page and shared with online friends, according to security firm Sophos, which has been tracking this type of attack, which it calls "likejacking."
[See also: 'Likejacking' exploit fools Facebook users and friends]
Sophos earlier detailed other likejacking exploits based on other phrases, such as "The Prom Dress That Got This Girl Suspended from School" and "This man takes a picture of himself EVERY DAY for 8 years!" and more.
Sophos senior technical consultant Graham Cluley says the likejacking attack that attempts to gull users with the message 'Paramore n-a-k-ed photo leaked!' will take victims to a third-party Web site, which displays a message that says: "Click here to continue if you are 18 years of age or above." But don't do it, Cluley says, writing a blog on the topic.
"What the hackers have actually done is very sneaky. They have hidden an invisible button under your mouse, so wherever you click on the website your mouse-press is hijacked. As a consequence, when you click with the mouse you are also secretly clicking on a button which tells Facebook that you 'like' the webpage. This then gets published on your own Facebook page, and shared with your online friends, resulting in the link spreading virally," Cluley writes. It's technically similar to the earlier likejacking exploits in that it makes use of what's called an iFrame exploit.
He notes the same Web site associated with the Paramore likejacking attack is hosting another Web page containing a clickjacking attack related to "teen heart-throb singing sensation Justin Bieber," that claims his phone has been leaked.
Cluley says Facebook should consider altering how 'liking' is executed online. "It's clear that Facebook needs to tighten up the way it handles the 'liking' of external webpages before it is even more widely abused by malicious hackers and spammers."
Cluley speculates that the likejacking exploits recently seen may be a proof-of-concept attack that could lead to more dangerous use of this type of exploit in the future, such as spreading dangerous malware.
Read more about wide area network in Network World's Wide Area Network section.
Facebook Watch
- Facebook may be driving deal for Waze mobile app
- Facebook on a mobile roll
- Facebook rethinks its 'hackathons' with an eye toward mobile
- On Facebook, men talk about music, women discuss family and friends
- Facebook Home hits 500K downloads
- After public dumping of social network, GM returns to Facebook ads
- Facebook Home goes after mobile market with 'ferocity'
- Will more smartphones support Facebook Home?
- Diversifying Facebook Home could broaden its appeal, analysts say
- Update: Facebook unveils Android Home screen and app family
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- File Archiving - The Next Big Thing or Just Big This white paper from Osterman Research discusses best practices for archiving file-based content and offers some recommendations about how organizations should manage the...
- 3 Steps to Unlock Savings from Legacy Applications Explore a three step process to free your business from unnecessary costs and to protect your business from unnecessary risks.
- Red Hat JBoss Fuse Compared with Oracle Service Bus Competitive Brief Read this paper to learn how to start more projects, deploy technology more pervasively within the enterprise, and apply more of your budget...
- Red Hat JBoss BRMS Best Practices Guide Learn the technical best practices for development with Red Hat JBoss Enterprise BRMS. Following the best practices outlined in these guides will result...
- Boost Performance & Profitability with Better Planning & Mobile Reporting This session will discuss how Ashurst, a top-tier legal service provider for private and public sector clients worldwide, was able to effectively manage...
- Apps and BlackBerry 10 - Tips for IT Learn how to easily create, deploy and manage both off-the-shelf and custom apps, improving productivity and efficiency for employees by mobilizing apps, processes... All Applications White Papers | Webcasts
Our weekly newsletter will cover a wide range of topics and trends related to consumerization. Stay up to date with news, reviews and in-depth coverage of BYOD, smartphones, tablets, MDM, cloud, social and how consumerization affects IT. Subscribe now!
