14 Jun 2010
Security researchers have spotted a new click-jacking scam on Facebook which spreads through the site's news feed and 'Like' feature.
UK security vendor Sophos issued a warning to users over what the company describes as a "like-jacking" attack.
The attack appears as a link to a web page offering photos of the '101 hottest women in the world.' The link presents a page which, when clicked, forwards the victim to a third-party site, and accesses their news feed without notification.
Clicking on the page activates the 'Like' feature on Facebook which allows people to share pages. The page then appears on the news feeds of the victim's connections, spreading itself to a new crop of potential targets.
No actual malware code is installed, and the updates can be manually removed from the status feed.
Graham Cluley, senior technology consultant at Sophos, explained that the scam makes money by generating advertising traffic.
Facebook was hit by a similar attack in May, and Cluley warned that the site needs to step up its security measures.
"Facebook really needs to grab this problem by the horns, as it is increasingly being struck by click-jacking worms," Cluley wrote in a blog post.
"The social network should tighten up the way it handles the 'liking' of external web pages before it is more widely abused by malicious hackers and spammers."
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Project Manager, London - Software Solutions (Project...
Project Manager - Hampshire - up to £32K - Fixed Term...
Senior Customer Support Consultant - 2nd/3rd Line Support...
C++/C#/Java developer for a global investment bank within...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?