Categorized | Security

Facebook scammers go back to using Javascript

Facebook scammers know that in order to keep users falling for their scams, they have to use a variety of approaches.

For example, there was a time where rogue applications were the scammers’ preferred method of making sure that the scheme is propagated through the social network. Before that, they were more partial to trying to make the users copy/paste scripts into their address bars in order to achieve the same result.

As users become accustomed to ignoring one particular approach – and Facebook is becoming more adept at spotting and blocking the rogue apps – the copy/paste script one makes a comeback.

The most popular lure used by these scammers is the undying “See who viewed your profile” offer. The landing page could be a Facebook one or one hosted on another domain, and it asks the user to copy some Javascript into the browser address bar and press ?Enter?.


And just in case the user does not understand the instructions, the scammers have attached a video of the whole process. Once the directions are executed, the user is (predictably) asked to fill out a survey in order to finally get the results. In the meantime, the Java script works its magic.

“Depending on the configurations of the attacker, the script will post a new bait message to the user?s wall, send chat messages to friends, tag you in post messages or images, or even create an event and send an invitation to all your friends,” explains Symantec.

“Of course as always the attack is easy configurable through a toolkit. Since the script runs in the context of Facebook and uses your open session it can do a lot with your profile, it can do nearly everything you could do yourself.”

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
2 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
2 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
2 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
2 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
2 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
2 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
2 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
2 months ago
Some free-based music we play at work http://t.co/xu5agZfc
2 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
2 months ago