The Register® — Biting the hand that feeds IT

Feeds

Rash of Facebook 'likejacks' still flaring

On Facebook, no one knows you're a bot

Customer Success Testimonial: Recovery is Everything

Facebook attacks that force users to unwittingly endorse scam pages keep spreading, researchers say.

When the exploits surfaced on Tuesday, they resulted in hundreds of thousands of users giving their thumbs up to links with titles including: "LOL This girl gets OWNED after a POLICE OFFICER reads her STATUS MESSAGE." Since then, similar attacks have circulated that cause users to recommend pages promising naked pictures of alternative rock diva Hayley Williams or the phone number of heart-throb singer Justin Bieber.

The attacks exploit a flaw present in virtually every browser that allows unscrupulous webmasters to control the links a visitor clicks on. They work by overlaying an invisible iframe or other web object on top of a link or blank space on a webpage. The result is that a user can never be sure he's clicking on the link or button he thinks he is. The exploit has been coined “clickjacking” by Jeremiah Grossman and Robert “RSnake” Hansen, the security researchers who brought the technique to public awareness in late 2008.

So far, there are no reports that the Facebook attacks amount to much more than pranks that cause users to click a “Like” button that recommends a link to their friends. But it's not inconceivable that the “likejacking” exploits could be used in much the way black-hat search engine optimization is used to lure people to websites that try to install malware on their machines.

There's only so much Facebook can do to stop the exploits since the actual clickjacking takes place on websites controlled by the attackers. Still, engineers could probably do better at isolating and then blocking the users or bots that are perpetuating the scam. Until then, remember that the number of “Likes” an ad or other piece of content boast on Facebook is largely meaningless. ®

Ensure Ease of Recovery with Asigra’s Agentless Software

Surprised....

This article was posted over 10 hours ago but as yet there doesn't seem to be a single "Facebook is Shit" or "All Facebook Users are Retarded" comment in this forum.

El Reg's commentards are slipping it would seem, where's the smug (yet mis-placed) superiority, where's the arrogance, where's the snobbery? I think we should be told....

3
0
Anonymous Coward

Here you Go

"Facebook is Shit"

"All Facebook Users are Retarded"

2
0

@ Beaker's Love Child

"where's the smug (yet mis-placed) superiority, where's the arrogance, where's the snobbery?"

Try looking in the mirror.

*high five*

1
0

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence
 breaking news
Yes, maybe we should keep hackers in the clink for YEARS, mulls EU
Watch out black hats, they just might throw away the key
Microsoft borks botnet takedown in Citadel snafu
Stupid Redmond kicked over our honeypots, wail white hats