Skip to navigation
   
Asavin Wattanajantra's Blog

Beware of hacked Facebook applications

By Asavin Wattanajantra in Editorial

Posted in antivirus, AVG, applications, Facebook on October 15, 2009 at 2:20 pm

Permalink | Author Profile

Being the Facebook junkie that I am, I’ve been playing a lot of the applications as I am generally quite a sad person. However, there was a bit of security news today that perhaps maybe should convince me that I need to be a little bit more careful.

Roger Thompson, chief research officer for security firm AVG, writes in a blog post about an attack which looks more serious than the usual way that social networks can sometimes link to hacked sites.

He says that actual Facebook applications are being hacked - not by the actual developers of the apps but bad guys looking to piggy back on their popularity.

He used an example of an app called CityFireDepartment, an online game where a player is supposed to play a role at being a fireman.

Once you have added the app, instead of playing the game the victim is presented with a fake Adobe licence agreement, followed by spyware downloaded onto the computer if you are unpatched.

At first Thompson and his team believed it was a deliberate hack by the developers, but it was actually caused by a outsider who has an iframe into the source code.

The line of malicious code changes once a day, and calls to a different exploit site.

He said: “Initially, we thought that the applications were deliberately acting as lures, but it now seems to us that they are victims themselves.

“The difficult part for them will be to find and plug the hole that the data snatchers are using to hack the applications.”

He names the other Facebook apps affected as MyGirlySpace, Ferrarifone, Mashpro, Mynameis, Pass-it-on, Filinthe and Aquariumlife.

12345
Rated: 60% (2 votes)
Loading ... Loading ...

 

   
Tag cloud

Kindle rickrolling university of portsmouth smartphone ID cards instant messaging crime map Google ASA Kaminsky kill browser alibi fire crime offline Steve Jobs eBooks Facebook flashmob Beijing worm Microsoft Farmville ducks data breaches hack Star Trek social media teenagers military IM journalism virtual worlds Dark Market Second Life IT PRO murder brainwaves mobile app opinion Spotify top ten tips downloading Google Maps Fraud Mafia Wars Firefox video games hacking Daily Mail pride Nintendo Google Street View news Twitpocalypse pod casting status uSwitch video tech MMORPG RPG Cisco Friendfeed YouTube robots Google Sonic phishing human clones unlimited FBI Lewis hamilton brain Mozilla Sophos multimedia Wherecloud future Mario flaw hatred BERTI NHS tool replies malware credit card data BlackBerry legal ENISA Olympics control cybercrime trend micro DNSSEC staff traffic satnav Scrabble Apple old school RSS David Blunkett Transformers Twitter medials hype Google Reader Christmas flexible working remote working SQL injection pirate morph feed Republicans swear words fun vote death spam phone password Bill Gates website growth Pirate Bay Flurry Klingon government software Sega alcohol lapto Black Hat hackers iPhone PR sightings research illegal science surveillance bendy streaming Digital Britain Digg James Bond funny Clampi internet World of Warcraft nokia paranoia broadband music filters Amazon privacy DNS poking Hitwise update Terminator sony playstation Nintendo Sega Sinclair Spectrum gaming Mario Sonic cyber crime
Advertisement
Advertisement