Categorized | Facebook

Italian model exposed in Facebook clickjacking attack

The mere mention of anything with a sex connotation on Facebook almost always begets some major activity, with people wanting to know more. As a result, whatever the attack vector or channel might be is propagated, and the attacker is sure to get some response.

 

In this example a Facebook click-jacking attack jumped on the bandwagon of Italian model Marika Fruscio's unfortunate incident with a wardrobe malfunction on live TV.  The title of the scam on Facebook was "The beautiful Marika Fruscio shows her breasts on Italian TV!", which almost sounds like it was staged as opposed to an accident.  Whatever the theory, the interesting part of this attack is what happens when someone clicks on the provided link to watch the embedded video.

 

The example seems harmless as upon clicking the link, the user is directed to another page where they can view the video.  While this is happening, the user's account is being exploited to post the video on their homepage to distribute.  The user is also added to the list of those who like the video, consequently encouraging others to view this.  The series of steps involved is shown below.

 

An infected account shows the advert as being liked either by a friend or contact within your Facebook account:

 

 

 

The user is then directed to the page below to view the video.  Unknown to the user, there are hidden elements and iframes within the HTML code, located at the Play button, which directly access the user's 'like' option within Facebook .  These hidden elements are where the magic of click-jacking, or shall we say like-jacking, happens.

 

Innocent-looking page as seen by the user:

 

 

Riddled page with hidden elements and iframe superimposed on the Play button and various parts of the page:

 

 

 

 

On clicking the Play button, two events take place. The first is that the user's Facebook account accepts 'liking' the video, with the video being posted on their wall as a result. The second is that the video plays Marika Fruscio's wardrobe malfunction on live TV. 

 

Below is the screen the user is presented with if they are not already logged in to Facebook:

 

 

 

The compromised account then displays a video link on the user's wall encouraging others to view this. 

 

 

 

There are several reasons for this type of attack and in this instance although there is nothing apparently malicious, it brings to mind the elaborate ploy where an attacker uses this means to earn some money.  Pay-per-click springs to mind, as attackers for these scams usually get the user to click on hidden links in order to get many hits, which then rewards the attacker with money.

 

Further analysis using our in-house tools on spontour.net shows the various links and how they are interconnected.

 

 

To protect yourself from attacks such as these, and also from posts like this being posted on your wall, try our free Defensio Facebook app.

 

 

Related Posts
  • Facebook clickjacking: Malware takes on new Italian disguises
    Non-English speaking Facebook users shouldn't be fooled into believing that they are somehow immune from the scams and attacks that plague the social networking site. The latest few campaigns seen by ...
  • Facebook clickjacking: Dirty Italian schoolteacher undresses
    Italian users could be at risk of being clickjacked on Facebook, as a new attack is seen spreading between users. SophosLabs has been seeing some detections of Mal/FBJack-A from Italian users, as they...
  • Facebook Clickjacking Attack Strikes Home
    Last week Graham Cluley, Senior Technology Consultant for Sophos, warned in his blog about a sleazy Facebook scam involving "shocking content". The scam first demands you click a button to c...
  • Cheryl Cole clickjacking on Facebook, posing as a BBC news report
    Girls Aloud pop star Cheryl Cole, famous in the UK for her role as a judge on top TV show "The X Factor" which had its grand final last night, is being exploited by scammers on Facebook. Scammers are...
  • Facebook hit by new iPhone spam attack
    Facebook users are being warned about a new spam scam that tries to tempt users into visiting a website with the promise of a free Apple iPhone. View full post on Network World on Security...
  • Facebook Clickjacking Attacks: Recognize and Avoid Them
    So far the clickjacking attacks that are making the rounds on Facebook haven't done more than forcibly gather web traffic. Learn to recognize and avoid them now, before a more dangerous version surfac...
  • Facebook Under Cyber Attack
    www.comodointernetsecurity.com Internet security insider visionary Melih Abdulhayoglu explains the underlying reasons why Facebook and other social networking sites hav...
  • In Action… Facebook Attack
    This attack demonstrates how a communication from facebook can contain malicious code that will infect the computer of the recipient. It helps explain how criminals are...
  • Facebook Warns of Clickjacking Scam
    Security firm Sophos recently discovered a new clickjacking scam on Facebook that spreads via the social network's "share" feature and could be costing you $5 a week. The new malware is similar to a s...
  • Facebook Warns of Clickjacking Scam (PC World)
    PC World - Security firm Sophos recently discovered a new clickjacking scam on Facebook that spreads via the social network's "share" feature and could be costing you $5 a week.  The new malware is s...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago