Skip to navigation
   
Asavin Wattanajantra's Blog

Beware of hacked Facebook applications

By Asavin Wattanajantra in Editorial

Posted in antivirus, AVG, applications, Facebook on October 15, 2009 at 2:20 pm

Permalink | Author Profile

Being the Facebook junkie that I am, I’ve been playing a lot of the applications as I am generally quite a sad person. However, there was a bit of security news today that perhaps maybe should convince me that I need to be a little bit more careful.

Roger Thompson, chief research officer for security firm AVG, writes in a blog post about an attack which looks more serious than the usual way that social networks can sometimes link to hacked sites.

He says that actual Facebook applications are being hacked - not by the actual developers of the apps but bad guys looking to piggy back on their popularity.

He used an example of an app called CityFireDepartment, an online game where a player is supposed to play a role at being a fireman.

Once you have added the app, instead of playing the game the victim is presented with a fake Adobe licence agreement, followed by spyware downloaded onto the computer if you are unpatched.

At first Thompson and his team believed it was a deliberate hack by the developers, but it was actually caused by a outsider who has an iframe into the source code.

The line of malicious code changes once a day, and calls to a different exploit site.

He said: “Initially, we thought that the applications were deliberately acting as lures, but it now seems to us that they are victims themselves.

“The difficult part for them will be to find and plug the hole that the data snatchers are using to hack the applications.”

He names the other Facebook apps affected as MyGirlySpace, Ferrarifone, Mashpro, Mynameis, Pass-it-on, Filinthe and Aquariumlife.

12345
Rated: 60% (2 votes)
Loading ... Loading ...

 

   
Tag cloud

bendy Black Hat phishing Twitpocalypse rickrolling feed filters legal Transformers Apple vote Farmville Bill Gates Hitwise Terminator phone Amazon status satnav medials malware James Bond brainwaves Spotify YouTube future credit card data PR Twitter replies David Blunkett Digital Britain remote working brain Lewis hamilton opinion lapto Microsoft Sega internet Olympics website Kindle worm software journalism SQL injection Flurry flashmob fun death crime map Google Google Street View news app Beijing alibi Scrabble Clampi Klingon fire flaw offline Google Reader Google smartphone trend micro uSwitch poking broadband music update multimedia Second Life hackers BERTI social media pirate unlimited tool password Christmas kill Digg Friendfeed Mafia Wars Steve Jobs crime virtual worlds data breaches Firefox privacy military swear words Kaminsky Cisco iPhone teenagers Star Trek research illegal Fraud tech Nintendo pride Facebook NHS mobile RSS science funny IM pod casting ID cards human clones BlackBerry traffic Republicans staff growth RPG ducks eBooks government alcohol IT PRO hype sightings flexible working surveillance nokia Mario video DNS Sophos control hatred instant messaging morph FBI Mozilla murder Sonic top ten tips World of Warcraft downloading Google Maps MMORPG paranoia hacking DNSSEC university of portsmouth ASA video games streaming old school spam browser cybercrime Dark Market ENISA hack Wherecloud robots Daily Mail cyber crime Pirate Bay sony playstation Nintendo Sega Sinclair Spectrum gaming Mario Sonic
Advertisement
Advertisement