Home » Headline, Security

Facebook gets hit twice in a week

28 February 2009 No Comment


The last weekend, many Facebook users got a notification stating that some of their friends “has faced some errors when checking your profile”. It also provided a link for the user to click and “View the Errors Message” which would lead to a lot of personal information being shared by unsuspecting users. More details can be found in Trend Micro’s anti-malware blog.

Last afternoon, a similar threat surfaced on Facebook, where many users were “reported by their friends for violating Facebook Terms of Service”. This provided a link to “check why you were reported”, which once clicked would send the spam to everyone in their friends’ network.

Some users have been able to avoid it once they noticed the sloppy spelling in the messages - but not everyone were that lucky.

Facebook has responded saying that they have disabled the application and additional versions that have sprung up, for violating the Facebook Developer Terms of Service. They state that they are actively monitoring the site for others and are working to block the application completely.

Being an application developer in Facebook is quite easy. All you have to do is to provide a valid e-mail address to get an application key. This allows virtually anyone to develop applications, and third-party applications are not evaluated before they hit the public. So, chances are that similar applications can crop up at another place at some point in time.

The best approach for Facebook users now would be to “look suspiciously” at any new applications before installing them on your profile. And, do a bit of research, ask Facebook or probably ask your friends in case you see anything out of the ordinary.

Popularity: 1% [?]

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.