The International Forum On Biotechnology
  • Home
  • Forum
  • Current Events
  • Our Blog
    • General Blog
  • News
    • Biotechnology News
    • Job Opportunities
    • Newspaper
  • Media
    • Picture Gallery
    • Videos
    • Files
  • Tech's Corner
  • Members Area
    • Subscribe To Us
  • Contact Us
    • Email
  • About Us
    • Location
  • Collaborators
  • Sub-domain Links
    • Mailing List
    • Forum
    • Newspaper
    • Blog
    • Gallery
    • Biot Mail
  • Disclaimer / Terms and Conditions

Clickjacking Worm Hits Facebook

6/1/2010

0 Comments

 
Picture
Affects hundreds of thousands of users

A clickjacking worm that forced hundreds of thousands of unsuspecting Facebook users to unknowingly post spam messages on their profiles, rapidly spread through the social networking website over the weekend. The worm used catchy news headlines to lure its victims into the trap.

Clickjacking is a Web attack technique that involves hijacking users' mouse clicks on a page (hence its name) and using them to trigger unauthorized actions. The attack is technically known as user interface (UI) redressing because it hides a clickable object, such as a button, by making it transparent and superimposing it over a non-dangerous looking one.

Though not new, the technique was only brought into the public attention last year, when reputed Web security researchers Jeremiah Grossman and Robert Hansen disclosed some critical attacks based on it. One of them allowed ill-intent hackers to turn on a computer's Web camera and microphone by exploiting a bug in the Flash Player Settings Manager.

The latest Facebook worm seems to be a proof of concept, becuase it does nothing destructive and its only purpose is to propagate. The offending messages posted on its victims' profiles are based on real and catchy news topics from the past several months. "LOL This girl gets OWNED after a POLICE OFFICER reads her STATUS MESSAGE", "This man takes a picture of himself EVERYDAY for 8 YEARS!!", "The Prom Dress That Got This Girl Suspended From School", or "This Girl Has An Interesting Way Of Eating A Banana, Check It Out!" are some of the examples.

Clicking on the messages takes users to external pages hosted at blogspot.com, which only display a text that reads "Click here to continue." However, clicking anywhere on the page abuses a user's active Facebook session to publishing a spam message back to his profile.

"The trick, which uses a clickjacking exploit, means that visiting users are tricked into 'liking' a page without necessarily realising they are recommending it to all of their Facebook friends. […] If you believe you may have been hit by this attack, view the recent activity on your news feed and delete entries related to the above links. Furthermore, you should view your profile, click on your Info tab and remove any of the pages from your 'Likes and interests' section," advises Graham Cluley, senior technology consultant at Sophos, who's antivirus products detect this threat as Troj/Iframe-ET.

To protect themselves, Mozilla Firefox users can install and use NoScript, a browser extension, which includes protection against clickjacking attacks, amongst others.

0 Comments

    Abraham Samuel

    abrahamsamuel@gmx.com

    Archives

    July 2012
    March 2012
    January 2012
    December 2011
    October 2011
    July 2011
    June 2011
    April 2011
    March 2011
    February 2011
    January 2011
    June 2010
    May 2010

    Categories

    All
    Anonymous
    Arrests
    Avast!
    Avira
    Behavior/Humans
    Biotechnology
    Box Office
    Brain
    Chemistry
    Clickjacking
    Climate Change
    Facebook
    Fbi
    Fund-raising
    Genetics
    Global Warming
    Harry Potter
    Health
    Jimmy Wales
    Kaspersky
    Lulzsec
    Microbiology/Genetics
    Movie
    Mse
    Nature
    Nod 32
    Paypal
    Physics
    Release
    Sequel
    Space
    Ui Redressing
    Web Attack
    Wikimedia Foundation
    Wikipedia
    Worm

    RSS Feed

    View my profile on LinkedIn
    Copyright © 2010-2014 The International Forum On Biotechnology ®  WWW.BIOT.TK ®  All rights reserved.
    By Using This Website You Agree To Our Terms and Conditions .

    Creative Commons LicenseCreative Commons License
    The International Forum On Biotechnology by Abraham Samuel is licensed under a Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported License.
    Based on a work at www.biot.tk.
    Permissions beyond the scope of this license may be available at http://www.biot.tk/disclaimer--terms-and-conditions.html.
Powered by Create your own unique website with customizable templates.