Skip to navigation
   
Asavin Wattanajantra's Blog

Beware of hacked Facebook applications

By Asavin Wattanajantra in Editorial

Posted in antivirus, AVG, applications, Facebook on October 15, 2009 at 2:20 pm

Permalink | Author Profile

Being the Facebook junkie that I am, I’ve been playing a lot of the applications as I am generally quite a sad person. However, there was a bit of security news today that perhaps maybe should convince me that I need to be a little bit more careful.

Roger Thompson, chief research officer for security firm AVG, writes in a blog post about an attack which looks more serious than the usual way that social networks can sometimes link to hacked sites.

He says that actual Facebook applications are being hacked - not by the actual developers of the apps but bad guys looking to piggy back on their popularity.

He used an example of an app called CityFireDepartment, an online game where a player is supposed to play a role at being a fireman.

Once you have added the app, instead of playing the game the victim is presented with a fake Adobe licence agreement, followed by spyware downloaded onto the computer if you are unpatched.

At first Thompson and his team believed it was a deliberate hack by the developers, but it was actually caused by a outsider who has an iframe into the source code.

The line of malicious code changes once a day, and calls to a different exploit site.

He said: “Initially, we thought that the applications were deliberately acting as lures, but it now seems to us that they are victims themselves.

“The difficult part for them will be to find and plug the hole that the data snatchers are using to hack the applications.”

He names the other Facebook apps affected as MyGirlySpace, Ferrarifone, Mashpro, Mynameis, Pass-it-on, Filinthe and Aquariumlife.

12345
Rated: 60% (2 votes)
Loading ... Loading ...

 

   
Tag cloud

smartphone Digg Flurry robots browser Beijing tool traffic Christmas Kaminsky Scrabble Farmville multimedia human clones Sophos Clampi tech medials Google Reader hatred cyber crime data breaches Lewis hamilton pod casting flashmob mobile Black Hat uSwitch brain credit card data Twitter hype opinion growth filters hacking worm status military streaming internet Mozilla Sega alibi science Mafia Wars Kindle Star Trek morph future social media phone ENISA spam illegal hack brainwaves Klingon swear words vote YouTube university of portsmouth Second Life murder surveillance feed legal Apple malware pride BERTI broadband old school control sightings Olympics SQL injection sony playstation Nintendo Sega Sinclair Spectrum gaming Mario Sonic funny staff eBooks Wherecloud update remote working downloading satnav iPhone Google Maps flexible working RSS Dark Market music Firefox Google Street View Sonic ASA Fraud phishing bendy alcohol kill Steve Jobs privacy virtual worlds video Nintendo Mario Bill Gates password trend micro crime map Google pirate Twitpocalypse offline video games crime lapto fire BlackBerry Pirate Bay Cisco World of Warcraft IT PRO rickrolling Google unlimited Facebook Microsoft Amazon MMORPG website app Spotify paranoia replies IM DNSSEC ducks teenagers flaw top ten tips NHS ID cards James Bond FBI Terminator Transformers hackers Digital Britain PR journalism news nokia government software David Blunkett death Republicans poking Daily Mail instant messaging Friendfeed RPG Hitwise cybercrime DNS research fun
Advertisement
Advertisement