‘Clickjacking’ epidemic spreads across Facebook

Washington, June 4 (ANI): Facebook seems to be facing an online epidemic – hundreds of thousands of Facebook users are falling in the “clickjacking” trap, according to web security labs.

Users are tricked into clicking links such as “World Cup 2010 in HD” or “Justin Bieber”s phone number” that their friends appear to have “liked”.

Once clicked, the site is recommended on Facebook too, and could pose danger of potential malware, even though currently there’s no such content on these sites. It also works across all computer operating systems.

The link generally takes the user through to a page containing an instruction, such as asking them to click a button to confirm that they are over 18.

However, wherever they click on the page it adds a link to their own Facebook profile saying they have also “liked” the site.

‘Clickjacking’ for now, is harmless, and does not actively result in any malware or phishing attacks, said Graham Cluley, senior technology consultant at Sophos.

“At the moment the attacks which we”ve seen are more like old-school viruses – written for the heck of it to see how many fans they can get.

“But our feeling is that it would be fairly easy for the bad guys to introduce some revenue generation for themselves,” BBC News quoted him as saying.

A free plug-in called NoScript, built for the Firefox web browser, includes pop-up warnings about potential clickjacks, but will also query clicks on Flash videos, commonly used on many websites – and it is not easy to install, said Mr Cluley.

“You have to be a little bit nerdy to configure it.” (ANI)

Over 50 pct Facebook users could delete accounts over privacy worries

London, May 20 (ANI): A security firm has suggested that more than half of Facebook users are considering deleting their profile from the site because of privacy concerns.

According to Sophos, a computer security organisation, concerns about privacy are running so high that 60 percent of the 1,588 Facebook users questioned said they were considering deleting their accounts.

A further 16 percent said they had already stopped using Facebook because they felt they had inadequate control over their data, while a quarter said that they would not be quitting the social networking site, which has almost 500 million users worldwide.

Facebook has attracted criticism in recent weeks for the perceived complexity of its privacy settings, and the fact that users have to opt-out of sharing some of their information with third parties, rather than give explicit consent by opting in.

Although Facebook is expected to look again at its privacy policy in the coming days, it may not be enough to halt an online campaign for a mass Facebook “suicide” on May 31, with thousands of users encouraged to delete their accounts.

“This poll shows that the majority of users are fed up with the lack of control that Facebook gives users over their data,” the Telegraph quoted Graham Cluley, senior technology consultant at Sophos, as saying.

“Most still don”t know how to set their Facebook privacy options safely, finding the whole system confusing.

“What”s needed is a fundamental shift towards asking users to ”opt-in” to sharing information, rather than to ”opt-out”.

“A mass exodus from Facebook seems unlikely, but users are clearly getting more interested in knowing precisely who can view their data.

“People use Facebook to share private information and are unlikely to want their holiday snaps or new mobile number accidentally popping up all over the Internet,” he added. (ANI)

Warning for Facebook users: ‘Sexiest video’ message contains malware

London, May 19 (ANI): Facebook users are being warned not to click on a message that promises to deliver the ‘sexiest video ever’, as when opened it leads to the download of a programme that fills the computer with junk.

The video link appears in newsfeed together with a picture of a pneumatic model or a woman on an exercise bike wearing a miniskirt.

According to Wired.co.uk, the malware installs ‘adware’ called Hotbar, which makes the creator money and will pop up adverts when Internet Explorer and Windows Explorer are used.

The toolbar’s buttons will change depending on the site, but it will generally open up more unpleasant sites if one clicks the buttons.

It will also install skins for Internet Explorer, Outlook and Outlook express and start collecting user data.

IT security and data protection company Sophos says thousands of people are falling for the trick.

A video demonstrating the scam has been posted to YouTube by Websense Security Labs.

“You may want to watch a sexy video, but you’re more likely to end up being plagued by pop-up advertising,” Sky News quoted Graham Cluley, senior technology consultant at Sophos, as saying.

“Not only is adware being installed on your computer, but the rogue Facebook application is posting the same message to all of your friends’ accounts,” he added.

Cluley also said that Facebook users hit by the attack are advised not to click on the links or allow the Facebook application to run.

Victims are urged to scan their computer with up-to-date anti-virus software, change passwords, and review all Facebook applications and settings. (ANI)

Hackers capitalise on Swayze’s death

Sydney, Sept 16 (ANI): Hackers are using Patrick Swayze’s death to push off spurious anti-virus software to Internet users and infect their computers with viruses.

The 57-year-old Swayze died of pancreatic cancer on Monday.

Many bogus websites claiming to provide information on the death of the Dirty Dancing star have mushroomed up.

Computer security company Sophos recently showed in a recent video that hackers list these sites on the first page of search engines like Google.

Visitors to these sites are asked for an anti-virus scan and the result shows that the user’s computer is infected by Trojans, which are actually not present. The sites then try to sell fake anti-virus software to the users to clean up their systems.

Many sites also infect the users’ computer with viruses that can crack passwords and credit card numbers and send them to the hackers.

Hackers have also used the deaths of Michael Jackson and Natasha Richardson to lead users to virus infected sites.

The Sydney Morning Herald quoted Sophos senior technology consultant Graham Cluley as saying: “Clearly the cybercriminals are no slackers when it comes to jumping on a trending internet topic, and are more professional than ever before in spreading their fake anti-virus scams.” (ANI)

Jackson virus and spam spreads on Internet

SAN FRANCISCO: Security researchers warned Thursday of the increasing levels of viruses and spam using Jackson’s name to snare unsuspecting users.

One e-mail carries the subject line “Remembering Michael Jackson” was circulating with a worm in tow. The e-mail has a zip file attached that infects victims if downloaded.

“The e-mail, which claims to come from sarah@michaeljackson.com, says that the attached ZIP file contains secret songs and photos of Michael Jackson,” Graham Cluley, senior technology consultant at Sophos, wrote on a blog. “However, the reality is that opening the attachment exposes you to infection – and if your computer is hit you will be spreading the worm onto other Internet users.”

Cluley said that the malware also spreads via USB memory sticks. Another e-mail promises an exclusive look at a YouTube video of the “last work of Michael Jackson,” but instead installs a malicious program that steals passwords.

Source –

http://economictimes.indiatimes.com/Jackson-virus-spreads-on-Internet/articleshow/4731724.cms

Twitterati should be aware of worms, warns experts

Washington, May 3 (ANI): Social networking site Twitter suffers security breaches, an expert has warned.

According to Graham Cluley of antivirus firm Sophos, the microblogging site is prone to viruses created in the Javascript web-programming language.

The Senior Technology Consultant revealed that these viruses were capable of sending short messages or “tweets” under the user’s name and may even send their pals to phishing sites.

Cluley explained: “A couple of hours after Twitter says it has [a virus] under control a new worm appears using the same attack.”

The British computer programmer further warned that deleting an embarrassing or incriminating tweet, which may have been sent accidentally, still existed on the Twitter site, being searchable forever.

He said: “I think deleted should mean deleted.” (ANI)

Cyber criminals target Facebookers

London, March 3 (ANI): Social networking giant Facebook has been hit by hackers looking to paw upon users’ valuable information.

According to security experts, the site has faced five different security threats in the past seven days.

Rik Ferguson, senior security advisor at Trend Micro, revealed that Facebook had been besieged with four malicious applications along with a new variant of the Koobface virus.

These rogue applications try to rob saleable data from the profiles of those who open the link, whose malicious nature remained hidden on social network sites.

“This is not just restricted to Facebook. It’s a growing trend. Though I’m surprised it’s taken so long for social sites to be targeted,” The BBC quoted him as saying.

Ferguson further suggested that the free-access website should consider policing applications.

However, Facebook chief Mark Zuckerberg declined the possibility in preference for an open system.

In a Radio 1 Newsbeat interview, he said: “Our philosophy is that having an open system anyone can participate in is generally better.”

Meanwhile, blogger Graham Cluley, also senior technology consultant at anti-virus software developers Sophos, said: “One of the problems is that Facebook allows anybody to write an application and third party applications are not vetted before they are released to the public.

“Even as Facebook stamps out one malignant application, it can pop up in another place.” (ANI)