<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: facebook]]></title>
    <link>http://securityratty.com/tag/facebook</link>
    <description></description>
    <pubDate>Fri, 08 Aug 2008 09:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Forgot your password? may be weakest link in web security]]></title>
      <link>http://securityratty.com/article/f121122122ae1d7763240a344ce2f35b</link>
      <guid>http://securityratty.com/article/f121122122ae1d7763240a344ce2f35b</guid>
      <description><![CDATA[Almost everyone forgets a Web site password once in a while. When you do, you click on the familiar Forgot your password? link. As an experiment, Thompson recently asked a few friends for permission...]]></description>
      <content:encoded><![CDATA[Almost everyone forgets a Web site password once in a while. When you do, you click on the familiar Forgot your password? link. As an experiment, Thompson recently asked a few friends for permission to "hack" into their bank accounts. Using only information gathered from Web sites such as Facebook, he found his way in to each account within minutes]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:27:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/web site password">web site password</category>
      <category domain="http://securityratty.com/tag/thompson recently">thompson recently</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/bank accounts">bank accounts</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/experiment">experiment</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <category domain="http://securityratty.com/tag/hack">hack</category>
      <source url="http://digg.com/security/Forgot_your_password_may_be_weakest_link_in_web_security">Forgot your password? may be weakest link in web security</source>
    </item>
    <item>
      <title><![CDATA[Facebook Malware Campaigns Rotating Tactics]]></title>
      <link>http://securityratty.com/article/62296c3643a587ae28183112d47c0996</link>
      <guid>http://securityratty.com/article/62296c3643a587ae28183112d47c0996</guid>
      <description><![CDATA[Trust is vital, and coming up with ways to multiply the trust factor is crucial for a successful malware campaign spreading across social networks . Excluding the publicly available malware modules...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVZhfsUzjI/AAAAAAAACH0/KTs0CyEnwvY/s1600-h/imageshack_flash_malware.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVZhfsUzjI/AAAAAAAACH0/rKZA6eLgyX8/s200-R/imageshack_flash_malware.JPG" /></a>Trust is vital, and coming up with ways to multiply the trust factor is crucial for a successful <a href="http://vil.nai.com/vil/content/v_148955.htm">malware campaign spreading across social networks</a>. Excluding the publicly available malware modules for spreading across <a href="http://ddanchev.blogspot.com/2008/01/myspace-phishers-now-targeting-facebook.html">popular social networking sites</a>, using the presumably, <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">already phished accounts</a> for the foundation of the trust factor, the recent malware campaigns spreading across Facebook and Myspace are all about plain simple social engineering and a combination of tactics.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVdgajolNI/AAAAAAAACH8/p5BY3A1kV5s/s1600-h/facebook_flash_redirector.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVdgajolNI/AAAAAAAACH8/EyJLoN6fQxg/s200-R/facebook_flash_redirector.JPG" /></a>However, in between combining typosquatting and on purposely introducing longer subdomains impersonating a web application's directory structure, there are certain exceptions. Like this flash file hosted at ImageShack and spammed across Facebook profiles, which at a particular moment in the past few days used to redirect to client-side exploits served on behalf of a shady affiliate network that's apparently geolocating the campaigns based on where the visitors are coming from.<br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLVjHR-P9vI/AAAAAAAACIE/Cx_1BIXZ1kY/s1600-h/facebook_blogspot_obfuscation.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLVjHR-P9vI/AAAAAAAACIE/WPYZNHd88gs/s200-R/facebook_blogspot_obfuscation.JPG" /></a><b>img228.imageshack .us/img228/3238/gameonit4.swf</b> redirects to <b>ermacysoffer .info</b> - (216.52.184.243) and to <b>tracking.profitsource .net</b> (67.208.131.124) that's also responding to <b>p223in.linktrust .com</b> (67.208.131.124). Just for the record, we also have <b>halifax-cnline.co.uk</b> parked at 216.52.184.243, 69.64.145.229 and 69.64.145.229, known badware IPs related to previous fraudulent activity.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVmUiQTZJI/AAAAAAAACIM/kpCUSo21ipU/s1600-h/facebook_malware_wall.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SLVmUiQTZJI/AAAAAAAACIM/d-GYBiTRhOI/s200-R/facebook_malware_wall.png" /></a>Moreover, cross-checking this campaign with <a href="http://www.bangky.net/blog/?p=257">another Facebook malware campaign</a> enticing users to visit <b>whitneyganykus.blogspot .com </b>where a javascript obfuscation redirects to <b>absvdfd87 .com</b> and from there to the already known <b>tracking.profitsource .net/redir.aspx?CID=9725&amp;AFID=28836&amp;DID=44292</b>, and given that absvdfd87.com is parked at the now known 69.64.145.229, we have a decent smoking gun connecting the two campaigns. <br />
<br />
Facebook is often advising that users stay away from weird URLs, does this mean ignoring <a href="http://ddanchev.blogspot.com/2008/06/imageshack-typosquatted-to-serve.html">ImageShack</a> and Blogspot altogether? The next malware campaign could be taking advantage of <a href="http://blog.trendmicro.com/malware-abuses-doubleclicks-open-redirects">DoubleClick</a> and <a href="http://www.virusbtn.com/news/2008/06_03a.xml?rss">AdSense redirectors</a> - for starters.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=lkuMCK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=lkuMCK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VN4CtK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VN4CtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pjIc8k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pjIc8k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uO3Bmk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uO3Bmk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gFnCxK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gFnCxK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4tQCAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4tQCAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=g7cSMk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=g7cSMk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/376254144" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:04:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware campaign">malware campaign</category>
      <category domain="http://securityratty.com/tag/successful malware campaign">successful malware campaign</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/facebook malware campaign">facebook malware campaign</category>
      <category domain="http://securityratty.com/tag/campaigns">campaigns</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/campaigns based">campaigns based</category>
      <category domain="http://securityratty.com/tag/trust factor">trust factor</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/376254144/facebook-malware-campaigns-rotating.html">Facebook Malware Campaigns Rotating Tactics</source>
    </item>
    <item>
      <title><![CDATA[Facebook Worm Still Going Strong]]></title>
      <link>http://securityratty.com/article/3d63cb5f4654a97b393266f752d1c56a</link>
      <guid>http://securityratty.com/article/3d63cb5f4654a97b393266f752d1c56a</guid>
      <description><![CDATA[A colleague of mine had a private message sent to them on Facebook yesterday from the account of a friend. The message is related (of course) to the recent Facebook worm





Click the link, and...]]></description>
      <content:encoded><![CDATA[
        A colleague of mine had a private message sent to them on Facebook yesterday from the account of a friend. The message is related (of course) to the recent <a href="http://blogs.pcmag.com/securitywatch/2008/08/facebook_worm_spreads_rapidly.php">Facebook worm</a>:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fbspam1.jpg" src="http://blog.spywareguide.com/images/fbspam1.jpg" class="mt-image-none" style="" height="304" width="413" /></span></div><br /> <div><br />Click the link, and you'll see something like this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fbspam2.html" onclick="window.open('http://blog.spywareguide.com/images/fbspam2.html','popup','width=700,height=510,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fbspam2-thumb-300x218.jpg" alt="fbspam2.jpg" class="mt-image-none" style="" height="218" width="300" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />Yes, it's Ye Olde Fake Codec installer, hosted on what appears to be a hacked website. As always, pay close attention to what you're being sent from your friends. If it doesn't <i>seem</i> like something they'd send you, that's probably because they didn't...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 05:57:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/recent facebook worm">recent facebook worm</category>
      <category domain="http://securityratty.com/tag/close attention">close attention</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/facebook yesterday">facebook yesterday</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/friend">friend</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <source url="http://blog.spywareguide.com/2008/08/facebook-worm-still-going-stro.html">Facebook Worm Still Going Strong</source>
    </item>
    <item>
      <title><![CDATA[Pass It On!]]></title>
      <link>http://securityratty.com/article/0b0eafc50e6acbced4bbec33d0e7057d</link>
      <guid>http://securityratty.com/article/0b0eafc50e6acbced4bbec33d0e7057d</guid>
      <description><![CDATA[Another day, another useless message being kicked around Facebook





If you see this, please - ignore it and tell your friends off for sending it to others in the first...]]></description>
      <content:encoded><![CDATA[
        Another day, another useless message being kicked around Facebook:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fbspam000.jpg" src="http://blog.spywareguide.com/images/fbspam000.jpg" class="mt-image-none" style="" height="95" width="323" /></span></div><br /> <div><br />If you see this, please - ignore it and tell your friends off for sending it to others in the first place ;)<br /></div>
        
    ]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 04:33:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/useless message">useless message</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/ignore">ignore</category>
      <source url="http://blog.spywareguide.com/2008/08/pass-it-on.html">Pass It On!</source>
    </item>
    <item>
      <title><![CDATA[Dont click that link, think first.]]></title>
      <link>http://securityratty.com/article/00f591f7bb48f5a7e02e423f7c206f30</link>
      <guid>http://securityratty.com/article/00f591f7bb48f5a7e02e423f7c206f30</guid>
      <description><![CDATA[If the links not from someone you trust, dont click it


clipped from it.toolbox.com

New Social Malware hits the street


As social malware goes, this is a good delivery mechanism for getting people...]]></description>
      <content:encoded><![CDATA[<div > If the links not from someone you trust, dont click it! </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/03707B22-62C7-452D-8FF5-857D11334BEA/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/e3fe0631-cdd6-43d5-bd03-3d96a01a28b8/03707B22-62C7-452D-8FF5-857D11334BEA/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://it.toolbox.com/blogs/managing-infosec/new-social-malware-hits-the-street-26676" href="http://it.toolbox.com/blogs/managing-infosec/new-social-malware-hits-the-street-26676" style="font-size: 11px;">it.toolbox.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://it.toolbox.com/blogs/managing-infosec/new-social-malware-hits-the-street-26676 -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">
		New Social Malware hits the street
	</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://it.toolbox.com/blogs/managing-infosec/new-social-malware-hits-the-street-26676 --><DIV>As social malware goes, this is a good delivery mechanism for getting people to click on links. Most of us have learned that clicking on links from people who you do not know is generally not a good idea. Spinning up the social aspect of malware delivery, using MySpace and Facebook friends should result in a better penetration of the malware because we are used to clicking on links from our friends.<br />
</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/03707B22-62C7-452D-8FF5-857D11334BEA/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 21:15:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/social malware hits">social malware hits</category>
      <category domain="http://securityratty.com/tag/malware delivery">malware delivery</category>
      <category domain="http://securityratty.com/tag/social malware">social malware</category>
      <category domain="http://securityratty.com/tag/links">links</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <category domain="http://securityratty.com/tag/facebook friends">facebook friends</category>
      <category domain="http://securityratty.com/tag/social aspect">social aspect</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=566">Dont click that link, think first.</source>
    </item>
    <item>
      <title><![CDATA[Facebook Attacked By Viral Social Networking Spam From China]]></title>
      <link>http://securityratty.com/article/f5d91dbb95f1d40eb6b47c52ab1b76d9</link>
      <guid>http://securityratty.com/article/f5d91dbb95f1d40eb6b47c52ab1b76d9</guid>
      <description><![CDATA[Websense Security Labs published a research of recent Facebook phishing email picked up by their Honeyjax system recently. Websense has been tracking various Facebook attacks for years, althoughh...]]></description>
      <content:encoded><![CDATA[Websense Security Labs published a research of recent Facebook phishing email picked up by their &#8220;Honeyjax&#8221; system recently. Websense has been tracking various Facebook attacks for years, althoughh attacks on Facebook and MySpace in the last few weeks are nothing new. There have been continual, targeted Facebook attacks for some time now.
The attack starts with [...]]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 06:42:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/recent facebook">recent facebook</category>
      <category domain="http://securityratty.com/tag/facebook attacks">facebook attacks</category>
      <category domain="http://securityratty.com/tag/websense">websense</category>
      <category domain="http://securityratty.com/tag/websense security labs">websense security labs</category>
      <category domain="http://securityratty.com/tag/honeyjax system recently">honeyjax system recently</category>
      <category domain="http://securityratty.com/tag/attack starts">attack starts</category>
      <category domain="http://securityratty.com/tag/althoughh attacks">althoughh attacks</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <source url="http://cyberinsecure.com/facebook-attacked-by-viral-social-networking-spam-from-china/">Facebook Attacked By Viral Social Networking Spam From China</source>
    </item>
    <item>
      <title><![CDATA[Facebook faces class-action suit over Beacon]]></title>
      <link>http://securityratty.com/article/ff6b5ab70cab7503321baa487c8b207e</link>
      <guid>http://securityratty.com/article/ff6b5ab70cab7503321baa487c8b207e</guid>
      <description><![CDATA[A class-action suit filed in California charges Facebook and a handful of other companies, including Blockbuster, Fandango and Overstock, with violating online privacy and computer fraud laws related...]]></description>
      <content:encoded><![CDATA[A class-action suit filed in California charges Facebook and a handful of other companies, including Blockbuster, Fandango and Overstock, with violating online privacy and computer fraud laws related to Facebook's controversial Beacon system.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=59428?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=59428?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/california charges facebook">california charges facebook</category>
      <category domain="http://securityratty.com/tag/class-action suit filed">class-action suit filed</category>
      <category domain="http://securityratty.com/tag/controversial beacon system">controversial beacon system</category>
      <category domain="http://securityratty.com/tag/computer fraud laws">computer fraud laws</category>
      <category domain="http://securityratty.com/tag/online privacy">online privacy</category>
      <category domain="http://securityratty.com/tag/fandango">fandango</category>
      <category domain="http://securityratty.com/tag/overstock">overstock</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <source url="http://www.networkworld.com/news/2008/081308-facebook-faces-class-action-suit-over.html?fsrc=rss-security">Facebook faces class-action suit over Beacon</source>
    </item>
    <item>
      <title><![CDATA[Marketing Bot Allows Insertion of Custom Facebook Feed Messages]]></title>
      <link>http://securityratty.com/article/41ee202ac244db0ab82c0ff056faa4a7</link>
      <guid>http://securityratty.com/article/41ee202ac244db0ab82c0ff056faa4a7</guid>
      <description><![CDATA[The Facebook News Feed is something that tells everyone on your friend list what both you (and everyone on your friend list) is doing, and it's the first thing you see when you login





Click to...]]></description>
      <content:encoded><![CDATA[
        The Facebook News Feed is something that tells everyone on your friend list what both you (and everyone on your friend list) is doing, and it's the first thing you see when you login:<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/feed0.html" onclick="window.open('http://blog.spywareguide.com/images/feed0.html','popup','width=582,height=565,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/feed0-thumb-382x370.jpg" alt="feed0.jpg" class="mt-image-none" style="" height="370" width="382" /></a></span><br /><br />Click to Enlarge<br /></div><br />Effectively, it takes bits and pieces of all the smaller feeds and rolls them into one. However, imagine instead of the above in your feed, you see something like this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/feed1.html" onclick="window.open('http://blog.spywareguide.com/images/feed1.html','popup','width=496,height=248,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/feed1-thumb-396x198.jpg" alt="feed1.jpg" class="mt-image-none" style="" height="198" width="396" /></a></span><br /><br />Click to Enlarge<br /></div><br />Those are customised messages inserted into your feed - and there's a good chance everyone on your Friends list will see it on their own feed when they login to Facebook.<br /><br />This would happen because someone has made a Bot for Facebook that allows you to insert your own custom message / image / clickable link into your Facebook feed. I've no idea if this is against the Facebook Terms of Service or not, but I can only imagine the chaos that would ensue if someone purchases this application then decides to use it for nefarious purposes. It's being promoted as a sales / marketing tool, but from a security standpoint it seems potentially disastrous.<br /><br />If a bad actor buys their own Bot, imagine the Myspace-style spam campaigns that could take place...everything from malicious URLs to obnoxious flashing banners could be the order of the day. At the very least, one would hope the makers of this Bot have some quality control going on with regards Bot owners. More <a href="http://forums.digitalpoint.com/showthread.php?p=8791542">here</a>.<br /><br />/ Hat-tip to <a href="http://www.ghettowebmaster.com/">LoLo</a><br /><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 09:26:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/feed">feed</category>
      <category domain="http://securityratty.com/tag/facebook feed">facebook feed</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/bot">bot</category>
      <category domain="http://securityratty.com/tag/facebook news feed">facebook news feed</category>
      <category domain="http://securityratty.com/tag/facebook terms">facebook terms</category>
      <category domain="http://securityratty.com/tag/bot owners">bot owners</category>
      <category domain="http://securityratty.com/tag/friend list">friend list</category>
      <category domain="http://securityratty.com/tag/myspace-style spam campaigns">myspace-style spam campaigns</category>
      <source url="http://blog.spywareguide.com/2008/08/marketing-bot-allows-insertion.html">Marketing Bot Allows Insertion of Custom Facebook Feed Messages</source>
    </item>
    <item>
      <title><![CDATA[FaceBook Under Massive Phishing Attack From China]]></title>
      <link>http://securityratty.com/article/47a657fc4d930aab9e7fff5ff8be5a2b</link>
      <guid>http://securityratty.com/article/47a657fc4d930aab9e7fff5ff8be5a2b</guid>
      <description><![CDATA[Facebook is under attack with numerous phishing scams and it looks like the network effect is coming into full swing to allow the prolification of these scammers to spread virally. The worrying thing...]]></description>
      <content:encoded><![CDATA[Facebook is under attack with numerous phishing scams and it looks like the network effect is coming into full swing to allow the prolification of these scammers to spread virally. The worrying thing about these scams is that they are increasingly sophisticated.]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 04:20:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/network effect">network effect</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/scams">scams</category>
      <category domain="http://securityratty.com/tag/scammers">scammers</category>
      <category domain="http://securityratty.com/tag/increasingly">increasingly</category>
      <category domain="http://securityratty.com/tag/prolification">prolification</category>
      <category domain="http://securityratty.com/tag/spread">spread</category>
      <category domain="http://securityratty.com/tag/numerous">numerous</category>
      <source url="http://digg.com/security/FaceBook_Under_Massive_Phishing_Attack_From_China">FaceBook Under Massive Phishing Attack From China</source>
    </item>
    <item>
      <title><![CDATA[Facebook stamps out malware attack]]></title>
      <link>http://securityratty.com/article/680eda1b732d79195c6135090192afbf</link>
      <guid>http://securityratty.com/article/680eda1b732d79195c6135090192afbf</guid>
      <description><![CDATA[Facebook has blocked a malware attack targeting unsuspecting users via postings on the site's Wall...]]></description>
      <content:encoded><![CDATA[Facebook has blocked a malware attack targeting unsuspecting users via postings on the site's Wall feature.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=EennBl"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=EennBl" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/359502944" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware attack">malware attack</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/wall feature">wall feature</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/postings">postings</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/359502944/article.do">Facebook stamps out malware attack</source>
    </item>
  </channel>
</rss>
