A number of games and other applications built to be used on Facebook.com have been hacked so that users are quietly sent to sites that try to install malicious programs, a security researcher has found. Roger Thompson, chief research officer for computer security firm AVG, discovered about a half-dozen Facebook games and app home pages had been compromised by attackers. While hacked Facebook profile pages are not uncommon -- thanks largely to threats like the Koobface worm -- Thompson said this was the first time he'd seen actual Facebook applications being hacked. According to Thompson, the hackers somehow slipped malicious "iframes" -- small, hidden chunks of computer code that invisibly load content from exploit sites -- into each of the Facebook.com Web pages where users would go to use the apps. The exploit sites in turn try to foist malicious software if the visitor is running outdated Adobe products, such
![]()
Exploits:
- Vuln: Mahara Resume Blocktype Cross Site Scripting Vulnerability
- Vuln: Mahara Admin Password Reset Security Bypass Vulnerability
- Vuln: eCryptfs 'parse_tag_3_packet()' Packet Heap Based Buffer Overflow Vulnerability
- Vuln: Cisco VPN Client for Windows 'StartServiceCtrlDispatche' Local Denial of Service Vulnerability
- Vuln: HP OpenView Network Node Manager 'ovdbrun.exe' Denial of Service Vulnerability
- Vuln: PHP Versions Prior to 5.3.1 Multiple Vulnerabilities
- Vuln: KDE KDELibs 'dtoa()' Remote Code Execution Vulnerability
- Vuln: PEAR Sendmail 'From' Parameter Arbitrary Argument Injection Vulnerability
- Vuln: IBM Rational Products Multiple Cross Site Scripting Vulnerabilities
- Vuln: Microsoft Internet Explorer 'Style' Object Remote Code Execution Vulnerability
News
Latest Security News
Researcher: Hackers Hijack Some Facebook Apps
Latest Security News
Researcher: Hackers Hijack Some Facebook Apps
A number of games and other applications built to be used on Facebook.com have been hacked so that users are quietly sent to sites that try to install malicious programs, a security researcher has found. Roger Thompson, chief research officer for computer security firm AVG, discovered about a half-dozen Facebook games and app home pages had been compromised by attackers. While hacked Facebook profile pages are not uncommon -- thanks largely to threats like the Koobface worm -- Thompson said ...
Viewed 446 times so far.
Like this? Tweet it to your followers!
Published in
Subscribe to the RSS feed of Network Security & Hacking News
Network Security & Hacking News
/
Subscribe to the RSS feed of Latest Security News
Latest Security News
Like this? Let your friends know now!
Rate this article
Latest articles from GSO
-
Bugtraq: Re: /proc filesystem allows bypassing directory permissions on Linux
posted on Monday, 29 November 1999 16:00
Re: /proc filesystem allows bypassing directory permissions on Linux
-
Vuln: IBM Lotus Connections Mobile Activities Pages Cross Site Scripting Vulnerability
posted on Monday, 26 October 2009 12:00
IBM Lotus Connections Mobile Activities Pages Cross Site Scripting Vulnerability
-
Bugtraq: Adobe Acrobat Reader up to 9.1.1 ONLY Linux integer overflow to heap overflow.
posted on Monday, 29 November 1999 16:00
Adobe Acrobat Reader up to 9.1.1 ONLY Linux integer overflow to heap overflow.
-
Bugtraq: Rising Multiple Products Local Privilege Escalation Vulnerability
posted on Monday, 29 November 1999 16:00
Rising Multiple Products Local Privilege Escalation Vulnerability
-
Bugtraq: {PRL} Rising Firewall 2009 Privilege Escalation
posted on Monday, 29 November 1999 16:00
{PRL} Rising Firewall 2009 Privilege Escalation
Latest 'tweets' from GovernmentSecurity
- News Update: Cyber war is coming, the impact could be huge: CBS News reports that cyber.. http://bit.ly/1tx1kr | #Security Link Monday, 09 November 2009 07:35
- News Update: Tenable Network #Security Podcast - Episode 11: Welcome to the Tenable Netw.. http://bit.ly/2Iqd6G | Security Link Monday, 09 November 2009 07:35
- News Update: Consent will be required for cookies in Europe: EDITORIAL: A law that dema.. http://bit.ly/3JYgip | #Security Link Monday, 09 November 2009 07:35
- News Update: CBS 60 Minutes tackles cyber-terrorism: Could hackers get into the compute.. http://bit.ly/2d5Y21 | #Security Link Monday, 09 November 2009 07:35
- Blog Update: We have launched the new GovernmentSecurity.org: We decided to launch th.. http://bit.ly/2G1SSF | #Security Link Saturday, 07 November 2009 17:38
Site Search
Login Form
Disqus Tools
