site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
649
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies


Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub
kudos:4

FBI warns of social networking fraud, malware escalation

Social networking sites hit with all manner of spam, phishing, malware and general fraud
Networkworld | 10/01/09

Fraudsters are targeting social networking sites with increased frequency and users need to take precautions, the FBI warned.

Just today Roger Thompson, chief of research at AVG Technologies, blogged about an automated rogue spyware attack using Facebook in which hackers create new Facebook pages. "We're seeing rather a lot of these, all from different profiles, but with the same picture and link. Clearly, the Data Snatchers have found a way to automate the creation of Facebook accounts, which means they've found a way to bypass the Facebook Capcha (the image of letters which are required for a new account, which are supposed to ensure that a human is involved)," stated Thompson.

The FBI meanwhile states that fraudsters continue to hijack accounts on social networking sites and spread malicious software by using various techniques. One technique involves the use of spam to promote phishing sites, claiming there has been a violation of the terms of agreement or some other type of issue which needs to be resolved. Other spam entices users to download an application or view a video. Some spam appears to be sent from users' "friends", giving the perception of being legitimate. Once the user responds to the phishing site, downloads the application, or clicks on the video link, their computer, telephone or other digital device becomes infected, the FBI stated.

Another fraudster favorite involves applications advertised on social networking sites, which appear legitimate; however, some of these applications install malicious code or rogue anti-virus software, the FBI stated.

Other malicious software gives the fraudsters access to your profile and personal information. These programs will automatically send messages to your "friends" list, instructing them to download the new application too, the FBI stated.

Symantec's Zulfikar Ramzan wrote in a recent CSO article that there's no question that online social networking continues to rise in popularity due to the numerous conveniences and opportunities it provides. There's also no question that social networking provides phishers with a lot more bait than they used to have. Threats can come from all sorts of avenues within a social networking site. Games, links and notifications are the low-hanging fruit for phishers to use as they lead people into dangerous territory. As society picks up one end of the social networking stick, it finds that it inevitably picks up the security problems on the other end, he stated.
»www.networkworld.com/community/node/45809
--
Smokey's Security Forums »www.smokey-services.eu/forums/
Smokey's Security Weblog »smokeys.wordpress.com/
Official Jetico Inc. Support Forums »www.smokey-services.eu/


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX

Here's a prime example of that, encountered when Mike Burgess (winhelp2002) was doing some investigation of several suspect domains at Google Diagnostic:

said by Hosts News blog :
Phishing for Facebook

While researching several suspect domains at Google Diagnostic ... Landing on "uxfl.co. cc"
which redirects to a IP address that tries to mimic a Facebook page complete with a bogus Flash player upgrade. As you can see my AV NOD32 jumped up and killed the connection, as the page automatically downloads a malicious file ...

»msmvps.com/blogs/hostsnews/archi···998.aspx
--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub
kudos:4

Txs for the example Doctor!



DSL_Steve
Premium
join:2003-11-28
Woodbury, CT

reply to Doctor Four

said by Doctor Four:

Here's a prime example of that, encountered when Mike Burgess (winhelp2002) was doing some investigation of several suspect domains at Google Diagnostic:

said by Hosts News blog :
Phishing for Facebook

While researching several suspect domains at Google Diagnostic ... Landing on "uxfl.co. cc"
which redirects to a IP address that tries to mimic a Facebook page complete with a bogus Flash player upgrade. As you can see my AV NOD32 jumped up and killed the connection, as the page automatically downloads a malicious file ...

»msmvps.com/blogs/hostsnews/archi···998.aspx
What version NOD32 are you running?


NOYB
St. John 3.16
Premium
join:2005-12-15
Forest Grove, OR
kudos:1

reply to Smokey Bear
...which means they've found a way to bypass the Facebook Capcha (the image of letters which are required for a new account, which are supposed to ensure that a human is involved)," stated Thompson.

Cool. It's about time someone proves capcha useless. Surprised it has taken as long as it has. There are better ways that are automated and do not require any extra user action.

--
Be a Good Netizen - Read, Know & Complain About Overly Restrictive Tyrannical ISP ToS & AUP »comcast.net/terms/ »verizon.net/policies/
Say Thanks with a Tool Points Donation



siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17
Reviews:
·Bell Sympatico

reply to Doctor Four
Doctor Four See Profile the phising domain IP's have not yet been included in the MVPS HOSTS File They may be manually added using the HOSTS Editor



fatness
subtle
Janitor
join:2000-11-17
fishing
kudos:13
Host:
Bright House Netwo..
Earthlink DSL
TekSavvy
Forum Feature Requ..
Need Site Help

1 edit

reply to Smokey Bear
When I read articles like this my first thought is "some expansion of government regulatory/surveillance power is about to be introduced."

Please don't take that as me faulting the OP. What was posted is an important issue whether my suspicions are correct or not.
--
"That blast came from the pants! That thing's operational!"


Monday, 06-Feb 22:57:36 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online! © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics