Facebook infested with new worm; More proof site is insecure?
Summary: Facebook is infested with a new worm, hijacking status updates and spreading like wildfire to other users. Another bit of evidence towards Facebook being insecure, and lax with user privacy and data?
Facebook is littered with a worm, seemingly the same one under different names, created by randomly generated developers, which is spreading links all over the site.
Applications like S22BZ5 created by randomly assigned pseudonym 'Jackson Lasseter' has nearly 300 people under the grips of the worm. Others, such as replicated application B5DA8G, 9IHJ35 and AU0ZVE have just under 1,000 people inadvertently spreading the worm.
Just in the last 24 hours, I have seen my own friends' list infiltrated by these worm applications which set status messages via the application without the knowledge of the profile owner, through a shortened link service with an infected GIF file.
A quick Facebook search for 'tiny.cc' and 'is.gd', two link shortening services, shows a great deal of worry and concern over
Links seem to run through imgcrave.info and imgpant.info which then direct the user to an ordinary, legitimate website like Google or YouTube. Once this is done, your Facebook will be compromised, though this only seems to work on a Windows machine.
By looking at the statistics on the tiny.cc webpage alone, it shows nearly 1,000 Facebook users clicking spam the link, with most being unique account holders running Windows with Firefox or Internet Explorer.
Running an WHOIS on both domains seem to pull up the registered details of a person living in the north of the United Kingdom, with the website based on a server in Denmark. This could fit considering the aforementioned statistics shows more people in the UK being hit by the worm.
This could however be a complicated 'revenge' attack on this person, considering any hacker or malware writer would surely not be stupid enough to leave their own details on a WHOIS record. This is speculation, however.
Once again, this shows Facebook will allow applications which are not verified, that act in a worm or malware like fashion, and allows individual user privacy to become compromised to anyone who can slap together a simple application.
Have you found yourself compromised by a worm application like this? Did you manage to remove it, or did it leave malware on your computer?
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
RE: Facebook infested with new worm; More proof site is insecure?
Any "secure site" no matter how secure can be broken into if enough people try hard enough, that does not make it insecure it makes it broken into.
Insecure is if it is easy or has no security at all like many people's WiFi.
Facebook is popular so who knows how many people try very hard every second to get in.
RE: Facebook infested with new worm; More proof site is insecure?
RE: Facebook infested with new worm; More proof site is insecure?
This is the poof that Facebook really does not give a damn about their customers. It is such an obvious security hole, yet they do nothing to plug it.
This is why, when to my horror, I saw a cute young thing in a Starbucks using her laptop for both facebook and home banking, I explained the risk to her, explaining why I am a "Facebook refusenik",why I would certainly never use Facebook on the same machine as home banking, even with Avira and Superantispyware (which I also recommended to her).
RE: Facebook infested with new worm; More proof site is insecure?
they sure are tight about any post reguarding it. I tried to post a link to this blog, won't take it. tried to post a portion of this text, rejected. seems they really don't want their users to know
RE: Facebook infested with new worm; More proof site is insecure?
I just posted a link to this article with no problems.
RE: Facebook infested with new worm; More proof site is insecure?
RE: Facebook infested with new worm; More proof site is insecure?
RE: Facebook infested with new worm; More proof site is insecure?
im qith you. At least when myspace had this issue, what three years ago, they redirected all links to pass through a page that says "hey you are leaving our site and could be at risk" ..
Sad thing is, that was three years ago and people are still too stupid to know the difference.
RE: Facebook infested with new worm; More proof site is insecure?
RE: Facebook infested with new worm; More proof site is insecure?
RE: Facebook infested with new worm; More proof site is insecure?
RE: Farmville, trustworthy...
RE: Facebook infested with new worm; More proof site is insecure?
facebook is becoming unfortunately a necessary evil... Using linux does reduce the risks accociated with these rogue apps. If you're an avid windows fan, install a virtualised Linux OS and use facebook there.
RE: Facebook infested with new worm; More proof site is insecure?
RE: Facebook infested with new worm; More proof site is insecure?
My E is: minor@bresnan.net Many thanks, Rick
RE: Facebook infested with new worm; More proof site is insecure?
RE: Facebook infested with new worm; More proof site is insecure?
Virtual Linux
p.s. I'm 63
RE: Facebook infested with new worm; More proof site is insecure?
By no means is it a -necessary- anything. I am a successful Facebook Refusenik.
New attack vector
Are there any browser add-ins which can decode/decrypt these URLs on the fly BEFORE you click them? It wouldn't help the masses of people who blindly click on stuff, but it would help those who are more self-aware and want to "sniff" the URL before clicking it.