Skip to navigation
   
Asavin Wattanajantra's Blog

Beware of hacked Facebook applications

By Asavin Wattanajantra in Editorial

Posted in antivirus, AVG, applications, Facebook on October 15, 2009 at 2:20 pm

Permalink | Author Profile

Being the Facebook junkie that I am, I’ve been playing a lot of the applications as I am generally quite a sad person. However, there was a bit of security news today that perhaps maybe should convince me that I need to be a little bit more careful.

Roger Thompson, chief research officer for security firm AVG, writes in a blog post about an attack which looks more serious than the usual way that social networks can sometimes link to hacked sites.

He says that actual Facebook applications are being hacked - not by the actual developers of the apps but bad guys looking to piggy back on their popularity.

He used an example of an app called CityFireDepartment, an online game where a player is supposed to play a role at being a fireman.

Once you have added the app, instead of playing the game the victim is presented with a fake Adobe licence agreement, followed by spyware downloaded onto the computer if you are unpatched.

At first Thompson and his team believed it was a deliberate hack by the developers, but it was actually caused by a outsider who has an iframe into the source code.

The line of malicious code changes once a day, and calls to a different exploit site.

He said: “Initially, we thought that the applications were deliberately acting as lures, but it now seems to us that they are victims themselves.

“The difficult part for them will be to find and plug the hole that the data snatchers are using to hack the applications.”

He names the other Facebook apps affected as MyGirlySpace, Ferrarifone, Mashpro, Mynameis, Pass-it-on, Filinthe and Aquariumlife.

12345
Rated: 60% (2 votes)
Loading ... Loading ...

 

   
Tag cloud

RPG David Blunkett software Lewis hamilton trend micro opinion nokia social media IM funny tool remote working swear words vote Daily Mail Amazon growth Transformers medials legal Klingon update PR worm Clampi Sega filters kill fire government hatred IT PRO Twitpocalypse NHS eBooks video games Nintendo Mozilla Beijing phishing password virtual worlds flexible working BERTI multimedia Cisco brainwaves Olympics BlackBerry Google Street View cyber crime ducks ID cards internet status broadband DNSSEC pride spam offline flashmob crime map Google Apple app Firefox murder paranoia crime uSwitch flaw Google Maps Christmas instant messaging morph replies bendy Bill Gates satnav phone Republicans Google Reader research Facebook Microsoft Steve Jobs future top ten tips DNS malware lapto unlimited Mafia Wars Mario Kaminsky credit card data robots science journalism sightings Sophos Digg Second Life traffic Twitter James Bond World of Warcraft surveillance tech Digital Britain Wherecloud streaming alibi data breaches alcohol hacking human clones Terminator SQL injection privacy rickrolling FBI Spotify mobile feed YouTube sony playstation Nintendo Sega Sinclair Spectrum gaming Mario Sonic university of portsmouth death old school pirate staff RSS Dark Market teenagers fun browser Friendfeed music illegal Hitwise control Black Hat ENISA hype video ASA iPhone downloading military Fraud Pirate Bay hack Sonic news Kindle Flurry poking cybercrime MMORPG Star Trek Farmville smartphone pod casting brain website Google Scrabble hackers
Advertisement
Advertisement