22 May 2010
Security experts are warning of a click-jacking worm spreading via Facebook which tricks users into posting it on their status updates, although it does not appear to be malicious.
F-Secure chief research officer Mikko Hyponnen said that the worm posts the following message: 'Try not to laugh xD http://www.fbhole. com/omg/allow.php?s=a &r=[random number]'.
Clicking on the link takes users to another page which displays a fake error message.
"If you click anywhere on the page, you will trigger a script that will try to post the same message to your Facebook wall," Hyponnen explained in a blog post.
"This is done with an invisible iFrame that follows your mouse around, causing you to click on an invisible 'publish' button. In addition to the wall message post, nothing else happens."
Hyponnen added that the worm is "spreading like wildfire", and that the domain referenced in the link, fbhole.com, points to an IP address in the Czech Republic.
Sophos senior technology consultant Graham Cluley added that thankfully the worm seems to have been created out of mischief rather than a desire to make money.
"Should we be surprised by this latest attack via Facebook? I don't think so, " he said in a blog post.
"One of the key findings of Sophos' 2010 Threat Report was about the astonishing 70 per cent rise in reports of malware attacks via social networks. Facebook, in particular, was named the riskiest of the social networks by survey respondents."
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
Orange and Intel talk us through the ins and outs of their San Diego smartphone
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
My client, a leading international name in Manufacturing...
My client is looking for an Automated Engineer/Developer...
*** Java Architect - IT Services/Consultancy - London...
Skills: C#, WCF, ASP.Net, Real Time Systems, MVC, SQL...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?