Skip to navigation
   
Davey Winder's Blog

One million Facebook users exposed to Zango worm

By Davey Winder in Editorial

Posted in Blog, Spyware, Facebook, Security, Internet on January 3, 2008 at 11:12 pm

Permalink | Author Profile

Given the popularity of Facebook applications, those annoying widgets which people in your network naturally assume you will be interested in (even though most are banal even by widget standards), it was only a matter of time before the trend was exploited by those with a less than social motive. And so it is that security threat researchers at Fortinet have uncovered a malicious widget which has already found its way onto the computers of 3% of Facebook users - or a million people if your prefer.

The Secret Crush application spreads by Facebook users getting a notification from someone in their network who has already installed the widget, which informs them that one of their friends has the hots for them. The wording is such that suggests it might be the friend who sent the invitation, but the only way to find out is to install the application itself. At this point the plot thickens, because using an escalation of commitment strategy Secret Crush the widget once installed will only reveal the identity of your secret admirer once you have invited another 5 of your friends to install it. According to Fortinet, even after inviting those 5 friends there is no revelation other than an invitation to download a ‘crush calculator’.

Fortinet has examined the page source of the advertising frame that is displayed and discovered it is hosted at zango.com, within the affiliates section. Downloading the application actually leads directly to a copy of Zango, the in famous adware/spyware that used to be known as 180Solutions. Download this and rather than a secret crush you will find yourself being courted by adverts.

Although there is no way of knowing the exact figures, the authors of Secret Crush are likely to be getting a few pence for every download, which multiplied by a million or two clicks soon adds up.

Fortinet CMO Richard Stiennon included “malicious Facebook widgets” in his list of security threat predictions for 2008, and it looks like he was right on the money. There seems to be no mechanism in place at Facebook to protect users from this kind of malicious application. Hackers could implement a similar scheme but replacing the Zango IFrame with a drive-by install engine instead.

“Keep in mind that, given the odds, people are likely developing Facebook “Platform Applications” for profit rather than just for fun. Now, this does not mean that all widgets are going to be malicious. As in every business frame, honest ways to generate profits surely exist on Facebook, in exchange for providing a service to users who subscribe to it. However, users must be aware of this, and resort to a blend of common sense and protection gear to avoid being scammed and abused” advises Fortinet EMEA Threat Response Team Manager Guillaume Lovet.

12345
Rated: 100% (1 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments
This article has no comments yet.

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

worker DNS Bill Gates rootkits banks Eee search gaming hardware Silverlight Trojan hubdub Digg Texas Instruments Flash Vista crime Battery report sick development holidays Supercomputer XP dumb iPhone 3G payments Firefox virtual world Gartner archiving Windows 7 Government library Blogging Business students BSI remote Noro e-commerce theft NBC hypervisor shopping Project work Hack Texting Linux data protection Olympics Rumour books stupid ID Theft home VPN data Paris Hilton world of warcraft SSL trust economics spam network man-in-the-middle scan credit card fraud web linkedin ecommerce digitise Twitter Video terrorism storage USA prison HPC documentation biometrics workplace security second life exploit size avatar hacking Space ISPA ASUS technology MessageLabs fraud survey policy botnet payment server symantec code science virus NASA adware Microsoft Web Development privacy chips Software IP environment Zango Windows Obama Big Brother scam christmas Yahoo computing BOFH Eee PC SMS InfoSec phishing Death web 2.0 Steve Jobs service Funny banking Finjan open source black hat teleworking virtual machine Apple social networking money Ballmer IDC The Federation CAPTCHA email productivity xmas Google China stupidity FBI scareware Facebook VM Mars Rant carbon copy Adobe Health printing malware copyright MiniBook Russia remote working betting OS AMD hacker MSNBC outsourcing Kill Switch politics Lotus Application broadband patch management green Internet Microchip graphics Top 500 iPhone tech migration transactional security help IBM fool OCR staffing fun Jesus Phone museum statistics worm mobile Energy global Performance computing Research millions universe computer standards office compromise news debian Deal Mobile Phone surveys MSN Programming
Advertisement
Advertisement
Advertisement