Facebook 'likejacking' attacks continue with flesh appeal
Network World - Facebook users are falling for yet another clickjacking scam that fools them into "liking" a page. This one lure victims with the message "Paramore n-a-k-ed photo leaked," which claims to point to a Web site containing a naked photo of Hayley Williams, lead singer in the rock band Paramore.
But clicking onward only brings the Facebook user to a page which, unbeknownst to the victim, has hidden code that executes the action of "liking" the Web page. That action gets published on the victim's Facebook page and shared with online friends, according to security firm Sophos, which has been tracking this type of attack, which it calls "likejacking."
Sophos earlier detailed other likejacking exploits based on other phrases, such as "The Prom Dress That Got This Girl Suspended from School" and "This man takes a picture of himself EVERY DAY for 8 years!" and more.
Sophos senior technical consultant Graham Cluley says the likejacking attack that attempts to gull users with the message 'Paramore n-a-k-ed photo leaked!' will take victims to a third-party Web site, which displays a message that says: "Click here to continue if you are 18 years of age or above." But don't do it, Cluley says, writing a blog on the topic.
"What the hackers have actually done is very sneaky. They have hidden an invisible button under your mouse, so wherever you click on the website your mouse-press is hijacked. As a consequence, when you click with the mouse you are also secretly clicking on a button which tells Facebook that you 'like' the webpage. This then gets published on your own Facebook page, and shared with your online friends, resulting in the link spreading virally," Cluley writes. It's technically similar to the earlier likejacking exploits in that it makes use of what's called an iFrame exploit.
He notes the same Web site associated with the Paramore likejacking attack is hosting another Web page containing a clickjacking attack related to "teen heart-throb singing sensation Justin Bieber," that claims his phone has been leaked.
Cluley says Facebook should consider altering how 'liking' is executed online. "It's clear that Facebook needs to tighten up the way it handles the 'liking' of external webpages before it is even more widely abused by malicious hackers and spammers."
Cluley speculates that the likejacking exploits recently seen may be a proof-of-concept attack that could lead to more dangerous use of this type of exploit in the future, such as spreading dangerous malware.
Read more about wide area network in Network World's Wide Area Network section.
- Marketers are losing faith in Facebook
- Facebook may lure teen users back with virtual reality promise
- Facebook's Oculus VR buy is about more than gaming
- Facebook spends $2B on virtual reality firm, but analysts are skeptical
- Facebook launches redesign with a bit of the old, a bit of the new
- Facebook eyes solar-powered drone company
- Facebook coughs up $19B for WhatsApp's younger users
- Facebook buying WhatsApp for $16 billion
- Facebook's birthday present: A look back at your social life
- At 10, Facebook strives not to be your granny's social network
- Silicon Valley's 19 Coolest Places to Work
- Is Windows 8 Development Worth the Trouble?
- 8 Books Every IT Leader Should Read This Year
- 10 Hot Hadoop Startups to Watch
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- CIOs Deliver Productivity Breakthroughs with Intelligent Digital Signage Retailers have long recognized the influence that digital signage provides over a shopper's point-of-purchase decision making process.
- ERP in the Cloud and the Modern Business View IDC's White Paper, to review IDC CloudTrack Survey findings, gain expert insight into the challenges and opportunities the cloud presents, and determine...
- Oracle ERP Cloud Service - Back-Office Solutions that Keep You in Front Learn how you can harness the power of the cloud to run your business more effectively and lower upfront costs.
- Integration with Oracle Fusion Financials Cloud Service While moving your financial system to the cloud may seem straightforward, truly realizing the advantages of the cloud requires a complete understanding how...
Transforming Finance, Procurement and Supply Chain Effectiveness with Cross-Functional Analytics
Date: May 6th, 2014
Time: 1 PM EDT
Attend this Webcast to find out how Oracle's packaged analytic applications enable line-of-business managers to examine all...
- Video Stream Quality Impacts Viewer Behavior This scientific white paper, using statistical data from Amakai's streaming network, analyzes how changes in video quality cause changes in viewer behavior. All Applications White Papers | Webcasts