Give your Desktop a Mozaic Touch

Experience the Windows 8 Metro Stlye UI on your Computer

Windows 7 God Mode

Get an Advanced Control Panel in Windows7 by enabling God Mode

Download Internet Explorer 9

Enjoy The Internet in a New and Secure Way

Microsoft Office 2010 Professional Activation

Activator for Microsoft Office 2010 Professional 100% Working..!!

Flash Wallpapers for Mobile

More than 175 Flash/SWF wallpapers for Mobile with System Info

Showing posts with label Facebook scams. Show all posts
Showing posts with label Facebook scams. Show all posts

Friday, March 30, 2012

Facebook profiles can be hijacked by Chrome extensions malware


Facebook+profiles+can+be+hijacked+by+Chrome+extensions+malware
          Cybercriminals are uploading malicious Chrome browser extensions to the official Chrome Web Store and use them to hijack Facebook accounts, according to security researchers from Kaspersky Lab. The rogue extensions are advertised on Facebook by scammers and claim to allow changing the color of profile pages, tracking profile visitors or even removing social media viruses.
 
Facebook+profiles+can+be++hijacked+by+Chrome+extensions+malware
          The attacks manifest as suggestions to download Facebook apps. Those apps are, alas, not real. Instead they are malware and, in one case, a malware-laden Chrome extension hosted in Google's very own Chrome Web Store. To do that, they must follow a series of steps, which include installing a fake Adobe Flash Player Chrome extension. The launchpad for the fake Flash Player is a Facebook app called “Aprenda”. If Aprenda is installed it redirects users to Chrome Web Store, encouraging them to install the fake Flash extension.

          “This last one caught our attention not because it asks the user to install a malicious extension, but because the malicious extension is hosted at the official Google's Chrome Web Store. If the user clicks on ‘install application’ he will be redirected to the official store. The malicious extension presents itself as “Adobe Flash Player”, wrote Fabio Assolini. "Be careful when using Facebook. And think twice before installing a Google Chrome extension," he adds.

          Uploading multiple rogue extensions on the Chrome Web Store and running several Facebook spam campaigns to advertise them allows attackers to quickly compromise thousands of accounts. The malware operates in much the same way as other Facebook scams, such as inviting friends to install it, however the purpose of the highjacking accounts is to generate fraudulent "Likes" which are sold for about US$27 per 1,000.

          Now, the extension Assolini found was concentrated in Brazil, where Chrome enjoys 45% of the browser market and Facebook is by far the most popular social network. That does not, however, mean that the problem is isolated to Brazil. The malicious extension was installed in numerous countries, including the U.S. With these potential security risks in mind, "Think twice before installing a Google Chrome extension".

Thursday, March 29, 2012

Facebook Profile Viewer rogue application spreads on social network

          Facebook Profile Viewer rogue applicationA rogue application which claims to allow you to see who has viewed your Facebook profile is spreading between accounts on the popular social network. Messages claiming that Facebook has issued a new update which allows you to check who has visited your profile are making the rounds.
Facebook Profile Viewer rogue application
Facebook Profile Viewer rogue application
New Update from facebook. Now you can check who visited your profile. check here -------->>>FAÅ’BOOK PROFILE VIEWER ®<<<<------
Who Watching your Profile ?
          If you are intrigued by the Facebook Profile Viewer enough to click on the link, you are asked to permit an application to access your profile. You should always be very careful, of course, about allowing applications to read and write to your

          Facebook profile. And this time is no exception. Because although at first you may believe that the application is showing you the details of people who have viewed your profile..
..behind the scenes, it is posting a message to your Facebook page without your explicit permission, encouraging others to also use the application.
Facebook Profile Viewer rogue application
          Clearly rogue applications like this could be used for scooping up personal information, or spreading spam and scams across the social network. So if you fell for it, remove the messages from your timeline, revoke the app's publishing rights and report it as spam to Facebook, and ensure that you have revoked its access to your account.


And remember this - Facebook does not give you any way to find out who has been viewing your profile. Any application or link which claims it can reveal to you who has should be treated with great suspicion.

Friday, December 16, 2011

Hacker who bypassed Facebook security pleads guilty


Facebook software engineering puzzle website

          A British student has pleaded guilty to charges that he breached security at Facebook earlier his year, despite arguing that his intentions were not malicious. York computer science student Glenn Steven Mangham, 26, attempted to bypass security on the company's internal systems, raising alarm amongst the FBI that industrial espionage was occurring, according to media reports.

         Mangham, who had previously been rewarded by Yahoo for finding vulnerabilities in its systems, discovered that Facebook was far from amused by his activities. The social networking giant discovered evidence that pointed back to Mangham and he was arrested by the Metropolitan Police Central e-Crime Unit (PCeU) in June.

         Specifically, Mangham was accused of using a computer program to secure unauthorized access to Facebook, of attempting to hack into Facebook's Mailman server (used to run internal and external email lists), and attempting to secure access to the Facebook Phabricator server used by internal developers.
Southwark Crown Court was told Mangham produced software scripts that could hack into Facebook's Phabricator server to download "highly sensitive intellectual property".

         In addition, the student was said to have breached a webserver used by Facebook to set software development puzzles to programmers who might be interested in working for the company. Mangham's defence team has argued that he was an "ethical" or "white-hat" hacker, whose intentions - rather than being malicious - were to uncover security vulnerabilities at Facebook with the intention of getting them fixed.
Facebook users will be relieved to hear that the social network told BBC News that the attack "did not involve an attempt to compromise or access user data."

         Thank goodness for that. Of course, Facebook founder Mark Zuckerberg's past is not necessarily entirely squeaky clean itself. In the past, he has been accused of hacking into a rival social network, breaking into journalists' email accounts, and calling Facebook's early adopters "dumb f**ks" for sharing their email addresses, photos and other personal information.

Thursday, December 15, 2011

Facebook Ticker partially Removed Due To Various Bugs

        According to a Post on Facebook Known Issues Page, Facebook has removed the ticker apparently motivated the social network to call the phenomenon a bug that’s undergoing a fix.

          Facebook says that "Some people are seeing their ticker disappear. We are aware of this issue and are working to resolve it.". Comments explaining that people with less active accounts won’t see the feature, Because when your friends aren’t doing anything on the site, the ticker would only duplicate the news feed and not scroll, so there’s no point in the feature taking up part of your screen.

          Not even this, Last month a Brazilian (independent) Security and Behavior Research had analyzed a privacy issue in Facebook Ticker that allows any person chasing you without your knowledge or consent .How Facebook Ticker exposing your information and behavior without your knowledge. Meanwhile, the Known Issues on Facebook page posted that some people aren’t seeing the ticker who should be, and that the site is working to fix this glitch and developers continues to refine the ticker, alternately testing labels for the feature along with shifting its location and size.

Wednesday, December 7, 2011

Facebook fixes flaw that allowed access to private photos


Move Fast and Break Things - poster at Facebook HQ

          In the end, it took a picture of Mark Zuckerberg holding a dead chicken to get Facebook to fix a flaw that allowed strangers to access your private photos.

          The social networking site allowed users to have access to other users' personal and private photographs that would normally be hidden from view - by taking advantage of a flaw in the "Report inappropriate profile photo" feature.

          The flaw worked like this. If you're a Facebook user , you can report other users' profile pictures as being "inappropriate". For instance, you can say that they contain "nudity or pornography". However, Facebook then gives an opportunity to select "additional photos to include with your report" and displays a selection of photographs - which may not be shared publicly.

          The flaw was highlighted on a body building message forum (yes, really..) but really got the world's attention when someone posted thirteen private photos from the Facebook account of Mark Zuckerberg.
In many ways it's good that Zuckerberg's account was targeted - if it such a high profile figure hadn't fallen victim, the flaw might have continued to have been exploited for much longer opening up opportunities for stalkers and others to view private photos.

          "Move fast and break things". That's a poster on the wall at Facebook's HQ, and is the company's internal motto. You'll notice the poster doesn't say "Privacy matters".

          In other words, Facebook's programmers are experimenting with new features and are testing them out on the live site without, in this case at least, the code being properly reviewed with privacy in mind.
The good news is that Facebook responded quickly once the problem made the tech headlines and the ability to report additional photos (and thus inadvertently see users' private photos) is currently withdrawn.
Facebook issued a statement to the media about the flaw:
"Earlier today, we discovered a bug in one of our reporting flows that allows people to report multiple instances of inappropriate content simultaneously."
"The bug, was a result of one of our most recent code pushes and was live for a limited period of time. Not all content was accessible, rather a small number of one's photos. Upon discovering the bug, we immediately disabled the system, and will only return functionality once we can confirm the bug has been fixed."
          It's good that Facebook has fixed the flaw, as it impacted the privacy of users (including its CEO), but it should never have happened in the first place. Maybe that's not such a bad idea. Facebook needs to stop making mistakes when it comes to its members' privacy. Once users' trust is broken, it will be very hard to restore.

Wednesday, November 30, 2011

New Facebook Worm installing Zeus Bot in your Computer

          Today another new attack on Facebook users with Zeus Bot comes in action. The researchers of Danish security firm CSIS, has spotted a worm spreading within the Facebook platform. A new worm has popped up on Facebook, using apparently stolen user credentials to log in to victims' accounts and then send out malicious links to their friends. The worm also downloads and installs a variety of malware on users' machines, including a variant of the Zeus bot.

          If followed, the link takes the potential victim to a page where he or she are offered what appears to be a screensaver for download. Unfortunately, it is not a JPG file, but an executable (b.exe). Once run, it drops a cocktail of malicious files onto the system, including ZeuS, a popular Trojan spyware capable of stealing user information from infected systems. The worm is also found to have anti-VM capabilities, making it useless to execute and test in a virtual environment, such as Oracle VM VirtualBox and VMWare.

          Zeus is a common tool in the arsenal of many attackers these days, and is used in a wide variety of attacks and campaigns now. It used to be somewhat less common, but the appearance of cracked versions of the Zeus code has made it somewhat easier for lower-level attackers to get their hands on the malware. Zeus has a range of capabilities, and specializes in stealing sensitive user data such as banking credendtials, from infected machines.

          "The worm carries a cocktail of malware onto your machine, including a Zbot/ZeuS variant which is a serious threat and stealing sensitive information from the infected machine," warn the researchers.The worm is hosted on a variety of domains, so the link in the malicious message may vary. Other servers are used to collect the data sent by the aforementioned malware and to serve additional malicious software.

           This type of thing is very rare to just send to your email without you requesting it so I would advise anyone who thinks that you may have seen an email like this to delete it and mark it as spam right away.

France: Discovered the biggest Facebook phishing



          Attacker has stolen more then 5000 usernames and passwords, using the fake domain to scam the victims. We suggest to all victims to change there passwords immediately!

Note: Please Don’t Try to login on this website.

Fake Facebook website: http://www.frfacebook.fr/

          If you suspect that you may have exposed your personal information to an unauthorized individual, you should:
  1. Change all of your passwords that were exposed.
  2. Contact the institution that was being masqueraded. (www.facebook.com)
  3. Tell them that your personal information has been exposed.
  4. Ask them to cancel any accounts affected.
  5. If the information provided can be used to access other institutions, contact them as well. For example, if your credit card number was exposed, contact your credit card company as well.
Next time be more cerful when someone send you suspicious website!

Tuesday, November 29, 2011

Spam attack hits Facebook's own Help Center

Spam messages in Facebook's help center. Click for larger version          The community forum on Facebook's Help Center has become overrun by spammers, making the self-help support community effectively useless.
 
          The spam messages, which at the time of writing are claiming to offer ways to watch live streaming video of American football games, appear to have been posted by bogus or compromised Facebook accounts. Clicking on the links typically takes you to a webpage which asks you to hand over your email address, claiming that you will be sent a program that will allow you to watch live streaming video of football games. The potentials for abuse or malicious attack are obvious - and we would recommend that no users click on the links.
Snippet of Facebook security infographic          The alarm was first raised about the spam attack by the unofficial Facebook privacy and security blog. Hours later, new spam messages are still appearing on the Facebook Help Center. Could it be that the spammers are taking advantage of the Thanksgiving holiday weekend, when Facebook's security team may be more lightly staffed than normal?

           Certainly it's embarrassing for the social networking website to have one of its own pages hit so significantly by spammers, when it has recently been lauding its achievements in the fight against Facebook spam. With approximately 800 million users on Facebook, spammers will continue to seek out holes in the site's armour and try to trick the unwary into clicking on their links. To have the best chance of success, Facebook needs 24 x 7 protection, every single day of the year, and to raise awareness of the risks amongst its userbase.

Exposing 25 Facebook phishing websites

          Geeks at Security Web-Center Found 25 Facebook and list them. Sometimes spammers create fake pages that look like the Facebook login page. When you enter your email and password on one of these pages, the spammer records your information and keeps it. This is called phishing. The fake sites, like the one below, use a similar URL to Facebook.com in an attempt to steal people's login information.
          The people behind these websites, then use the information to access victims' accounts and send messages to their friends, further propagating the illegitimate sites. In some instances, the phishers make money by exploiting the personal information they've obtained.

List of Fake Sites Collected by Security Web-Center:
http://www.sanagustinturismo.co/Facebook/
http://www.facebook.pcriot.com/login.php
http://deadlyplayerx.binhoster.com/Facebook/securelogin.php
http://facelook.shop.co/login.php
http://sigininto.horizon-host.com/facbook/facebook.php
http://custom-facebook.info/facebook.htm
http://www.profile.co.gp/facebook
http://s6.mywibes.com/facebook.htm
http://www.fjtech.us/
http://myoneid.site90.com/
http://facedook.co.gp/wwwfacebookcomprofilephpid100001548737188.htm
http://faceebook-com.bugs3.com/login/Secured_Re-login/index1.html
http://facebooook.axfree.com/
http://combatarms.free.fr/
http://sweed.web44.net/
http://thekshitij.in/facebook/index1.html
http://addgames.awardspace.biz/
http://www.profile.co.gp/facebook/
http://www.sjscheat.com/Hosting%20blogger/facebook
http://h1.ripway.com/denal/
http://1337r00t.13.ohost.de/r00tw00tkn00wn/
http://faacebok.zapto.org/
http://h4ck3rgadungan.adfoo.info/index1.html
http://www.2498.b.hostable.me/
Note: Please Don't Try to login on above listed websites.

           Recently, Facebook phishing emails are threatening to delete users’ Facebook accounts unless the victims pass along their account details within 24 hours, as Posted by NakedSecurity

A typical phishing scam reads like this:
LAST WARNING : Your account is reported to have violated the policies that are considered annoying or insulting Facebook users. Until we system will disable your account within 24 hours if you do not do the reconfirmation.
Please confirm your account below:
[Link Removed]
Thanks.
The Facebook Team
Copyright facebook © 2011 Inc. All rights reserved.

          The emails are entirely bogus. They are not coming from Facebook. Social media venues would not request financial information, nor would they request login details.The scams are, in fact, designed to steal credit card numbers and social media accounts.  When someone has been phished, their account will often start automatically sending messages or links to a large number of their friends. These messages or links are often advertisements telling friends to check out videos or products. If your Facebook account is automatically sending out spammy messages or links, secure it here.

         Make sure that when you access the site, you always log in from a legitimate facebook.com domain. A good rule of thumb is if a URL ends in facebook.com, it is owned by Facebook. For example, "en-gb.facebook.com" ends in facebook.com and is therefore safe and legitimate.

Thursday, November 17, 2011

Facebook scare: 2 lakh accounts hacked in Bangalore

          The recent Facebook hack has reportedly claimed over 2 lakh victims in Bangalore. According to a news report in Mid Day, some two lakh Facebook users in Bangalore had their accounts hacked and weblinks to their morphed pornographic pictures sent as feeds to friends and family.

          Quoting social networking analysts, the report says that more than 2 lakh Bangalore Facebook accounts were hacked. The cybercrime department too is reported to have received calls and complaints regarding the mass hacking. According to the report, there are around 50 posts on Facebook stating that the users are quitting the social networking site forever after being embarrassed before friends and family.

          Incidentally, according to a Bloomberg report, Facebook claimed that it has identified those responsible for the deluge of hardcore porn and violent images in some users' newsfeeds, and said it is working with its legal team "to ensure appropriate consequences follow." The social networking company made the statement after porn, pictures of extreme violence and faked photos of celebrities such as Justin Bieber in sexual situations had overrun the profiles of some Facebook users.

          Facebook said that it has "drastically limited the damage caused" by a spam attack that took advantage of a browser vulnerability. "Protecting the people who use Facebook from spam and malicious content is a top priority for us," Palo Alto, California-based Facebook said in a statement.

Tuesday, November 15, 2011

Facebook WON'T donate 45 cents per share for beaten boy's surgery. It's a hoax!


Beaten boy Facebook hoax

           Almost 200,000 Facebook users have been duped into sharing and reposting a message about a 14 year old boy who was allegedly beaten badly by his stepfather after protecting his little sister from being raped. The message, which comes attached to an image of a young boy's injured torso, claims that Facebook will donate 45 cents for the cost of life-saving surgery, every time that a user reposts or shares the message.
          A 14 years old boy got beaten half dead by his stepfather.He only tried to protect his little sister from being raped.Now he's struggling for his life,but doctors say he won't make it without a surgery.His mother doesn't have money to pay it.Facebook donates 45cents for every sharing or reposting.Please help.
           At the time of writing, over 181,000 people have reposted or shared the photo and accompanying message on Facebook. Every few seconds we can see more Facebook users passing it onto their friends.
Of course, the claim that Facebook is donating money is nonsense. Facebook is doing nothing of the sort - and if it were donating money to a young boy's surgery they surely would not base it upon the number of times a message or photo was shared.

          You'll notice that the message includes no information supporting the story, no link to an official Facebook blog announcing the initiative, no details on where in the world the boy might be, or links to news stories that corroborate the claim. There's not even a date when the incident is claimed to have taken place, which means that a hoax chain letter like this can have a life of its own and continue to spread many years after its first appearance.

          Facebook is a breeding ground for rumours, hoaxes and chain letters because users find it so easy to forward bogus alerts and poorly-researched warnings on to all of their friends at the click of a mouse.
If a friend of yours shares a message with you like this on Facebook, remind them about the importance of not spreading chain letters and suggest that they inform all of their friends that they were mistaken (maybe they could link to this article if anybody needs convincing?).

Shopping spree at Morrisons? Nope, another Facebook scam...


Facebook scam

          As we know, times are getting tougher, especially with the holidays approaching. Food prices are high, morale is low, so who wouldn't want nice big £150 gift card from Morrisons?
It seems simple enough. Share the page and comment "Thanks!" and that's it... wait a minute...
Facebook scam
          Look! Another gift card! It's my lucky day! And it's for Argos! I really could use (insert appliance/gadget/electronic here). Let's go and claim it!
Ah ha! There's the scam - the dreaded survey form.
The scammers earn commission the more people they manage to drive to online surveys.
Facebook scam           Filling out an online survey like the above always puts you at risk of giving over your personal information to the bad guys too. If they are the "nicer" scam artists, they will simply sell the info to third-party marketing firms. If they aren't so nice, all that info can potentially be used for identity theft.
We know that times are tough, and with holidays coming up it can make people a little more eager to believe in such scams, but in all honesty, the old adage continues to hold true. "If it's too good to be true, it is".
If it was reputable in any way, retailers would be advertising it themselves and you wouldn't just hear about it on random pages on Facebook.

Thursday, November 10, 2011

Hoax! Little boy needs 100 Facebook shares for a heart transplant


Little boy needs 100 shares to get a heart transplant Facebook hoax

           A new hoax is spreading between Facebook users, in the mistaken belief that sharing a picture of a sick boy in intensive care will grant him a heart transplant.
     If this little boy gets 100 shares he can get his heart transplant for free
          Of course, the message is nonsense - and simply clogs up Facebook users' walls and newsfeeds. Think about it - is it really likely that a child will be given a heart transplant simply because enough people like a photograph on Facebook?
Another version of the hoax reads as follows:
I NEED AT LEAST 10000 SHARES.
Plz share..... Heart surgery free of cost for children (0-10 Yrs) Ph : 080-28411500 It might save some1's life...! Sharing takes a second... in bangalore INDIA
More than likes, sharing can help !
          According to the Urban Legends blog on About.com, the telephone number belongs to the Sri Sathya Sai Institute of Higher Medical Sciences, Whitefield in Bangalore, India. The clinic gives free medical assistance, and does not base surgery upon anything related to Facebook.

          If a friend of yours shares a message with you like this on Facebook, remind them about the importance of not spreading chain letters and suggest that they inform all of their friends that they were mistaken (maybe they could link to this article if anybody needs convincing?).

Tuesday, November 8, 2011

G00d3y Penetrating Facebook Security, Found By Team Greyhat (TGH)

          Well known hackers group Team Greyhat (TGH) has found serious Security flaws in Facebook. According to TGH using that vulnerability an attacker can hijack any facebook group by removing the original Admin. They have named it "G00d3y" vulnerability. Core team member from TGH (R00t3r-tgh, X-terminal, Th3-R00t3r, Hunt009s, Skywalk3r, eRr00r, Zer0) has also written an exploit based on java script which is penetrating that newly found FB flaws. Recently Team Greyhat also hijacked and hacked the official Facebook Group of Hindustan Cyber Army by using G00d3y Exploit

          The above screen shots is clearly saying that TGH has hijacked the Hindustan Cyber Army group. They have replace the group logo and defaced the group by uploading their own photo. Also there they have clearly declared that the group has been hacked.For more information about this hack & to see the TGH official release click Here

          Due to security reason VOGH is not publishing the exploit. Facebook security team has also been informed by TGH.We also want to state that if Facebook does not pay attention then this newly found G00d3y Exploit can be cyber weapon for hijacking Facebook Groups.

Researcher finds major flaw in Facebook

          A security penetration tester discovered a major flaw in Facebook that could allow a person to send anyone on the social-networking site malicious applications. Nathan Power, a senior security penetration tester at technology consultancy CDW, discovered the vulnerability and publicly disclosed it Thursday on his blog. The flaw was reported to Facebook on Sept. 30, which acknowledged the issue on Wednesday, he wrote.

          Power, who could not immediately be reached, wrote that Facebook does not normally allow a person to send an executable attachment using the "Message" tab. If you try to do that, it returns the message "Error Uploading: You cannot attach files of that type." Power wrote that an analysis of the browser's "POST" request sent to Facebook's servers showed that a variable called "filename" is parsed to see if a file should be allowed. But by simply by modifying the POST request with a space just after the file name, an executable could be attached to the message.

          "This was enough to trick the parser and allow our executable file to be attached and sent in a message," Power wrote. A person would not have to be an approved friend of the sender, as Facebook allows people to send those who are not their friends messages. The danger is that a hacker could use social engineering techniques to coax someone to launched the attachment, which could potentially infect their computer with malicious software.

          Facebook representatives contacted in London did not have an immediate response on Thursday afternoon.

Sunday, November 6, 2011

Shop for free at Tesco? Beware - it's another Facebook gift card scam


Tesco scam messages on Facebook

          In the last few days we have warned Facebook users about scams spreading on Facebook claiming that the likes of ASDA, Argos, Pizza Hut, Tim Hortons and Starbucks are offering consumers gift cards and vouchers entitling them to free goods.
Now it's the turn of British supermarket giant to find its brand abused by scammers attempting to earn money by driving internet traffic towards online surveys.

          Here are some examples of what is spreading on Facebook right now.
Get a FREE Tescho Schop - Up to a value of £500!
[LINK]
To celebrate our birthday, we are giving away thousands of £500! Tesco Gift Vouchers Free
Shop For FREE at Tesco - FREE Tesco Gift Card
[LINK]
To celebrate our birthday, we are giving away thousands of Gift Vouchers FREE [LINK]
Win £500 Tesco Vouchers!
[LINK]
Tesco is giving away more 500 Quid vouchers! Everyone Loves Tesco's low prices for everything from food to stylish clothing.
          Of course, if you were fooled into participating in this scam you probably want to know how to clean up your Facebook account. Remove the message from your newsfeed, so you are no longer spreading it with your online friends and be more careful next time.
Update: Facebook's security team has successfully blocked this campaign, before more users are impacted. Cheers.!!

Users baffled by Facebook privacy changes: survey


Facebook privacy

          Many have never even changed the default privacy settings, according to Which?

          Facebook users cannot keep up with the vast number of changes made to privacy settings over the last few years, according to a Which? Computing survey.

          According to the magazine, the social network giant, which has over 700 million users, has made nine changes to its privacy settings over the last 18 months. According to The Telegraph 48% of those polled by Which? said they agree with the statement, "I can't keep up with the number of changes Facebook has made to its data security settings."

          What's more worrying is that a further fifth (19%) said they have never adjusted their Facebook privacy settings. "Many Facebook users have never changed their privacy settings and those who have do it far less often than Facebook makes changes," said Rob Reid, scientific policy adviser for Which?. "This may reflect a disregard or lack of awareness for privacy or, more worryingly, privacy fatigue stimulated by the dizzying number of changes."

          Facebook has made a number of changes to its privacy and security settings following concerns from users and security groups over its default settings. It recently unveiled changes that it said gives each user more control over their privacy by allowing them to set privacy controls for each individual post on the site.
Earlier this year it was revealed Facebook would be quizzed by Irish authorities over its handling of personal information. According to the Financial Times the Irish data protection commissioner will conduct a privacy audit of Facebook's activities outside the US and Canada. Facebook's European headquarters are in Dublin.
More recently Facebook has come under scrutiny from the German authorities over fears that is was tracking the Internet activity of users even after they had deleted their account.

Thursday, November 3, 2011

Germany pressures Facebook on tracking technologies

          A German data protection authority contends Facebook is tracking users even after they delete their accounts, and it wants the company to respond to this potential privacy violation by Monday.
Hamburg's Data Protection Authority (DPA) has published a report about how Facebook uses cookies, or small pieces of data stored in a person's Web browser that record browsing behavior, said Johannes Caspar, head of the agency.

          Caspar said if users do not give their consent, Facebook should delete information it has stored, in accordance with European privacy regulations. If the discussions break down, the Hamburg DPA will pursue legal options, Caspar said. The agency has the power to levy fines. The agency concluded that Facebook does not need to leave persistent cookies on a person's computer, some of which remain for up to two years even if they delete their accounts, Caspar said. "Our investigation gave no reason for the setting of cookies," he said.

          Caspar said his agency is waiting for Facebook technicians to provide an explanation. Facebook said in a written statement it would have provided information about how it uses cookies prior to the report and that it was "surprised and disappointed." Any publication by the DPA is incomplete until the agency has the full information about cookies, Facebook contended.

          Facebook has faced scrutiny before over how it uses cookies. The company maintains that when a person logs out of their account, the cookies that remain do not contain account-related identifiers.
The cookies are used for security reasons, such as identifying spammers and ensuring minors don't try to sign up to the service with a different age, the company said in a statement. It also uses cookies to identify computers used by more than one person to log into Facebook in order to discourage the use of the "keep me logged in" feature on those machines.

          But cookies can easily be deleted in Web browsers. Firefox has a setting, for example, to delete cookies once the Web browser is closed, effectively foiling efforts to collect consistent information from a computer. Other measures can also be used to foil data collection, such as the use VPNs (Virtual Private Networks), which can make a computer appear to have an IP (Internet protocol) address in, say, China, when the computer is actually in the U.K.

          Hamburg's DPA has another outstanding issue with Facebook. It is still awaiting a response from the company about its facial-recognition feature that automatically identifies a person's friends and suggests their name. The agency believe that users should have to give their consent before Facebook's systems store and study their faces to enable the feature.

Facebook denies vulnerability, then quietly fixes it

          Facebook has apparently fixed a vulnerability in its social-networking site after insisting it wasn't a weakness and didn't need to be remedied. Nathan Power, who works for the technology consultancy CDW, updated his blog on Tuesday to reflect that the flaw had been fixed. The problem allowed a user to send another user an executable attachment by using Facebook's "Message" feature.

          The sender and the recipient did not have to be confirmed friends. Power, who notified Facebook on Sept. 30, found that Facebook parses part of a POST request to the server to see if the file being sent should be allowed. Usually, executable files are rejected. But Power found that if he modified the POST request with an extra space after the file name for the attachment, it would go through. If a victim accepted the file, the person would still need to launch it in order for malicious software to be installed.
The danger is that Facebook could be used for so-called spear phishing, or targeted attacks with the intention of loading malware on a victim's machine.

         The style of attack has been successful against companies such as RSA, which leaked information related to its SecurID authentication and disclosed the issue in March. At least one defense contractor was subsequently attacked following the RSA breach. Facebook's security manager, Ryan McGeehan, said in a statement last week that a successful attack using the vulnerability would require social engineering and also would only allow the attacker to send an obfuscated renamed file to another user one at a time. Facebook this week continued to insist that a fix was not necessary.

Wednesday, November 2, 2011

Socialbot Network finds it easy to harvest data from Facebook users

           Socialbot paperIn their paper, "The Socialbot Network: When Bots Socialise for Fame and Money", researchers from the University of British Columbia describe how they managed to collect private data from thousands of complete strangers on Facebook, and infiltrate their friend networks, using "socialbots".

          The researchers - Yazan Boshmaf, Ildar Muslukhov, Konstantin, Beznosov and Matei Ripeanu - explain that a socialbot is automated software that can control a social networking account, and can perform basic functions such as posting messages and friend requests. Importantly, socialbots attempt to pass themselves off as being a real, living human being rather than computer code.
Hot or Not, I Love Quotes
    
           Although Facebook puts steps in place to try to avoid the automated creation of accounts, the researchers relate how it would be possible to use online services to break CAPTCHAs, and populated their bogus accounts' profile images with attractive photos from HotOrNot. Fake Facebook status updates were also easy to generate, using an API provided by iheartquotes.com for random sayings. The researchers warn that socialbots can infiltrate friend networks by connecting to users, and could even be used to spread misinformation and propaganda to influence others.

          Furthermore, a socialbot can be used to harvest personal information such as email addresses and phone numbers. Bring many socialbots together and you have a Socialbot Network (SbN), under the control of one person. Socialbot networkThe researchers built an Socialbot Network consisting of 102 Socialbots and a single botmaster, and ran the operation for eight weeks. During that time the SbN made 8,570 friend requests and recorded all of the profile information it was able to access from its newly found "friends".
And it wasn't just people who accepted the bogus friend requests who leaked personal information - the private data of other users who had not been infiltrated was also exposed.

          In all, the researchers' socialbots made Facebook friends with 3,055 people and grew its extended network to a total of 1,085,785 profiles. Interestingly, one of the researchers' findings was that the more friends someone has on Facebook, the more likely they are to accept a friend request from a socialbot.

Once the socialbots had befriended one person, they would then attempt to become Facebook friends with their friend's friends, and so on.. As they became more embedded within friend networks, the acceptance rate of friend request reached 60%.

          With their automated data-slurping network the researchers were able to gather 35% of all the personally identifiable information found on their direct networks, and 24% from extended networks. These bots also managed to gather 46,500 email addresses and 14,500 home addresses. On average, each socialbot collected 175 new "chunks" of publicly-unaccesible users' data per day. Clearly there's a lesson for Facebook users to learn there about the need to carefully vet who you allow to become your Facebook friend, and what information you choose to share online.

          The researchers also felt that Facebook's inbuilt security systems, known as the Facebook Immune System (FIS) should be improved. They found that FIS only blocked 20% of the accounts used by the socialbots - and this was only because of feedback from suspicious users who flagged the account as spam.
Curiously, all of the blocked accounts were posing as female users. In the researchers' opinion, Facebook's security team isn't taking the threat of automated accounts seriously enough:
"In reaction, we asked ourselves: what assumptions are made by the FIS that might be problematic? The answer came directly from the authors of the FIS: they state that 'fake accounts have limited virality because they are not central nodes in the graph and lack trusted connections. They also have no unique data or history'.
"Hence, we conjecture that the FIS does not consider fake accounts as a real threat. Fake accounts, however, are one of the main [online social network] vulnerabilities that allow a botherder to run a large-scale infitration campaign. Detecting and blocking such accounts - as early as possible - is the main challenge that [online social network] security defenses like the FIS have to overcome in order to win the battle against an SbN."
          By the end of the eighth week, the researchers voluntarily dismantled their Socialbot network - not because it had caught the attention of Facebook's security team, but because of the amount of internet traffic it was generating.
Facebook magnify"In total, the SbN generated approximately 250GB inbound and 3GB outbound traffic."
     Facebook's security team is unlikely to look kindly on people who conduct experiments such as that done by the university researchers, and users are reminded that under Facebook's terms of service you are not allowed to create fake profiles, should use your real name, and should only collect information from other users with their consent.