Skip to navigation
   
Asavin Wattanajantra's Blog

Beware of hacked Facebook applications

By Asavin Wattanajantra in Editorial

Posted in antivirus, AVG, applications, Facebook on October 15, 2009 at 2:20 pm

Permalink | Author Profile

Being the Facebook junkie that I am, I’ve been playing a lot of the applications as I am generally quite a sad person. However, there was a bit of security news today that perhaps maybe should convince me that I need to be a little bit more careful.

Roger Thompson, chief research officer for security firm AVG, writes in a blog post about an attack which looks more serious than the usual way that social networks can sometimes link to hacked sites.

He says that actual Facebook applications are being hacked - not by the actual developers of the apps but bad guys looking to piggy back on their popularity.

He used an example of an app called CityFireDepartment, an online game where a player is supposed to play a role at being a fireman.

Once you have added the app, instead of playing the game the victim is presented with a fake Adobe licence agreement, followed by spyware downloaded onto the computer if you are unpatched.

At first Thompson and his team believed it was a deliberate hack by the developers, but it was actually caused by a outsider who has an iframe into the source code.

The line of malicious code changes once a day, and calls to a different exploit site.

He said: “Initially, we thought that the applications were deliberately acting as lures, but it now seems to us that they are victims themselves.

“The difficult part for them will be to find and plug the hole that the data snatchers are using to hack the applications.”

He names the other Facebook apps affected as MyGirlySpace, Ferrarifone, Mashpro, Mynameis, Pass-it-on, Filinthe and Aquariumlife.

12345
Rated: 60% (2 votes)
Loading ... Loading ...

 

   
Tag cloud

social media staff replies World of Warcraft pride spam Fraud nokia video games opinion tool Kaminsky ASA fun alibi status Beijing top ten tips Wherecloud funny filters government hacking Pirate Bay brain BERTI growth research IM control website Sonic human clones Twitpocalypse fire Microsoft university of portsmouth death cyber crime Twitter Hitwise hype ENISA browser alcohol SQL injection James Bond RSS murder Apple RPG Kindle Klingon military BlackBerry science Lewis hamilton Clampi IT PRO Transformers paranoia Dark Market phishing downloading journalism flashmob flexible working crime hack hatred bendy MMORPG medials broadband crime map Google rickrolling kill streaming DNSSEC Bill Gates swear words Google Reader future Republicans DNS worm credit card data Google Sega NHS illegal satnav Nintendo Mafia Wars trend micro Digital Britain internet unlimited Daily Mail app uSwitch update David Blunkett traffic YouTube brainwaves phone Mario Facebook Scrabble ducks Star Trek Steve Jobs Sophos iPhone flaw poking music eBooks surveillance Second Life sightings password vote Amazon legal PR Digg Black Hat Friendfeed feed multimedia hackers lapto cybercrime malware Mozilla robots smartphone Google Maps software video Christmas Farmville Spotify virtual worlds FBI Cisco Flurry news privacy ID cards Firefox Olympics data breaches Terminator remote working offline teenagers sony playstation Nintendo Sega Sinclair Spectrum gaming Mario Sonic morph pirate mobile Google Street View tech instant messaging old school pod casting
Advertisement
Advertisement