Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 7th, 2010, 12:24 GMT · By

Facebook Users Tricked into Loading Malicious Code in Their Browsers

SHARE:

Adjust text size:


Facebook scam tells users to paste malicious JavaScript into their browsers
Enlarge picture
Security researchers from AVG warn of an ongoing Facebook scam which asks users to paste malicious JavaScript into their browser's address bar. Users are lured onto pages that claims to contain a video 99% of people can't watch until the end.

The rogue Facebook profile pages are called "99% of people can't watch this video more than 25 seconds" and display a picture of a girl using her palms to covering her face. Users who land on these scam pages are encouraged to click on the "Video Here!" tab, where a fake video player is displayed.

Rogue profile page liked by almost 600,000 users
Enlarge picture
Underneath the video player image there is a message which reads: "Copy the code below, paste it into your browser's address bar and press enter to load this video..Plz wait 7-8 secs for processing!!!" A text box below it contains obfuscated JavaScript code, which if pasted into the browser, automatically "Likes" the page and posts a rogue status update on the victim's profile, promoting it.

Multiple scam pages
Enlarge picture
"It’s not clear what the payload is at this point, because we’re still figuring it out, but it’s probably one of the sites that wants to charge you $9.95 a month automatically to your mobile phone account," Roger Thompson, chief research officer at AVG, writes on his blog. He also points out that the particular page he analyzed was "liked" by almost 600,000 users.

We were not able to locate that particular page ourselves, probably because it was already deleted by Facebook's security team. However we did find many identical ones which are still live at the moment and so far have been liked by thousands of users.

The "copy this code in your address bar" trick is not new. Just last week we reported on an Orkut phishing scam that tricked users into loading malicious JavaScript into their browsers by promising a free mobile credit recharge code.

You can follow the editor on Twitter @lconstantin

TELL US WHAT YOU THINK:

9,777 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Rogue Facebook App Tricks 170,000 Users

New Koobface Campaign Spotted on Facebook

Facebook Scammers Offer Secret Cows for Adoption

Facebook Scam Lures Users with Zynga Special Gifts

Facebook Affiliate Marketing Scam Abuses the Target Brand

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM