Facebook exploit toolkit dumbs down rogue app creation
Scary monster and super profile creeps
Agentless Backup is Not a Myth
Miscreants have begun selling a cut-price point and click Facebook rogue application generation tool, designed for script kiddies too clueless to code their own malicious application.
The rogue Facebook app creation tool kit is available is available at just $25, net security firm Websense reports.
The toolkit offers a means to direct surfers towards survey scams, spread malware or act as a tool in furtherance of click-fraud scams, all by following a simple set of instructions. Bogus applications generated via the tool, called Tinie Facebook Viral Application, would offer lures such as the supposed opportunity to check on who has been viewing a Facebook profile.
The functionality of one rogue tool created by the toolkit, Facebook Profile Creeper Tracker Pro, as well as the toolkit itself is explained in a blog post containing screenshots by Websense here.
Patrik Runald, senior manager of security research at Websense, described the toolkit as an example of the commoditisation of internet scams.
"The bad guys will continue to look to take advantage of every available resource on the Web, including Facebook, in an effort to make money or steal information," Runald explained. "With the introduction of exploit kits and the templates for rogue Facebook applications, like the one we just discovered, the threshold for entry for criminal activity is significantly lowered."
"These kits are increasingly becoming commoditised and, with it, the potential pool of attackers and victims increases." ®
COMMENTS
I have a cunning plan.
Buy kit. Reverse-engineer code. Close exploits. Simples.
"Facebook Profile Creeper Tracker Pro"
Gotta love the word "Pro" bolted onto the end of that one. As if "Facebook Profile Creeper Tracker" is really the kind of high class program a professional would use.
Honestly there's computer illeterate and then there's retardation.
If "Facebook Profile Creeper Tracker Pro" sounds like the kind of program you want in your toolkit, then go ahead and get pwned, you deserve it.
Would you..
So let me get this straight
Script Kiddie goes to site, sees malware kit and thinks good idea I will buy that!
Dodgy Site Owner thinks, great numpty wannabe hacker ;)
SK gives Credit card details to DSO
DSO Empties SK's bank account and sends anonymous email to police with SK's ip and has just got the guys money and removed a competitor.
I think the FBI/CIA/Mi5 should start up in business selling fake malware kits...

IT infrastructure monitoring strategies
Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider
Data control in the cloud
Cloud based data management
Agentless Backup is Not a Myth