Download the
Tom's Guide App from the AppsStore
News and trends on internet
/ mobile / "sound & picture" / IT
Yes No

Facebook: Two Phishes in One Day

- By - Source : Tom's Guide US

Facebook suffered two separate phishing attacks in one day.

Softpedia is reporting that Facebook was the subject of two recent phishing attacks taking place in a span of twenty-four hours, both attacking victims through the application aspect of the social website. The first was reported by security expert Christopher Boyd  (blog), claiming that the attack used an application called Customer Dispute, while the other phishing attack, reported by Rik Ferguson (blog), used a sex-themed application.

Boyd reported that the Customer Dispute application actually did not launch an application launch page, but rather cloned a Facebook URL that eventually led to a "404- Page Not Found" error. The error itself originated on hosting site Ridgeway, not Facebook, thus sending Boyd searching Google and discovering a hacker forum where the Customer Dispute author once resided. The author admitted to the crime long before Boyd discovered the scam, and removed the page. Ridgeway deleted that author's account, and the forum thread eventually disappeared.

The second phishing attack, discovered by Rik Ferguson, sent out numerous notifications to Facebook users, asking them to check out comments made on one of their posts; the notifications appeared as an application that supposedly had over 287000 fans. According to Ferguson, the hyperlinks in the notifications led users to a malicious website.

“The server loads up a JavaScript before immediately using HTTP meta refreshtags to pull up the real Facebook website and prompting the victim for their login credentials," he said. "The attack site is registered to an Arsen Tumanyan who allegedly resides in Armenia, the domain is registered through GoDaddy and the URL leads to an IP address that resolves to the Amazon Elastic Compute Cloud (EC2) cloud.”

Ferguson said that the attack did not directly steal financial data, but rather account credentials to send spam or other phishing attacks to other users.

Share:
10
Comments
X

Comments

ubernoobie 08/17/2009 9:23 PM
Hide
-1+

Hmm what happened to targeting MySpace?

tenor77 08/17/2009 9:29 PM
Hide
-5+

ubernoobie :
Hmm what happened to targeting MySpace?



MySpace is like sooooo yesterday......

hellwig 08/17/2009 9:44 PM
Hide
-14+

ubernoobie :
Hmm what happened to targeting MySpace?


MySpace is soo 2008. Get with the times grandpa!

Personally, I think we need to just get rid of all these stupid sites (Facebook, Twitter, etc...). If I want viruses on my computer or someone stealing my information, I'll just keep...er... start downloading porn. We just need to gear the internet to people who have some small amount of intelligence, rather than creating sites that beckon to morons and simpletons (regardless of your own intelligence, you have to admit there are plenty of stupid people using Facebook and Twitter). Remember when technology was for people who understood how to use it?

theLaminator 08/17/2009 11:23 PM
Hide
-1+

^ +1

nukemaster 08/17/2009 11:25 PM
Hide
-1+

hellwig :
I think we need to just get rid of all these stupid sites (Facebook, Twitter, etc...). If I want viruses on my computer or someone stealing my information, I'll just keep...er... start downloading porn. We just need to gear the internet to people who have some small amount of intelligence, rather than creating sites that beckon to morons and simpletons (regardless of your own intelligence, you have to admit there are plenty of stupid people using Facebook and Twitter). Remember when technology was for people who understood how to use it?


+99999

tipmen 08/18/2009 3:00 AM
Hide
-1+

Can anyone fill me in on Twitter im stilling trying to figure that one out

calmstateofmind 08/18/2009 12:20 PM
Hide
-0+

What I find really funny about Twitter is that they actually have a video on their homepage telling you what's so good about it, as if they have to convince you to use it in order for you to sign up. Lol.

dhvd79a 08/18/2009 4:32 PM
Hide
-4+

"Can anyone fill me in on Twitter im stilling trying to figure that one out"

Yes, it is for egotist who sincerely believe that everyone is interested in the details of their lives.

snarfeck 08/18/2009 4:38 PM
Hide
-1+

"Yes, it is for egotist who sincerely believe that everyone is interested in the details of their lives."

+99999^9

descendency 08/18/2009 5:03 PM
Hide
-1+

Tipmen :
Can anyone fill me in on Twitter im stilling trying to figure that one out


I think the creators of twitter are still trying to figure it out... but sox the cat has it down pat.