<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>InfoSec Tools, Tips &#38; Thoughts &#187; Malware</title>
	<atom:link href="http://infosec3t.com/category/attacks/malware-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosec3t.com</link>
	<description>Exploring topics in InfoSec and Cyber Security   including  practical approaches to risk management.</description>
	<lastBuildDate>Sat, 12 May 2012 03:05:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
		<item>
		<title>Don&#039;t install fake Facebook Antivirus</title>
		<link>http://infosec3t.com/2010/03/29/dont-install-fake-facebook-antivirus/</link>
		<comments>http://infosec3t.com/2010/03/29/dont-install-fake-facebook-antivirus/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 16:20:40 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2032</guid>
		<description><![CDATA[Alas, another day, another Facebook security alert. As soon as you install this malware, it will tag every single one of your friends in a photo in batches of about 20. It then posts that photo to your wall. This is what the photo looks like: If a Friend looking through the photos then clicks [...]]]></description>
			<content:encoded><![CDATA[<p>Alas, another day, another Facebook <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> alert.</p>
<p>As soon as you install this <a href="http://infosec3t.com/tag/malware-attacks/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Malware">malware</a>, it will tag every single one of your friends in a photo in batches of about 20. It then posts that photo to your wall.</p>
<p>This is what the photo looks like:</p>
<p><img class="aligncenter size-full wp-image-2033" title="Facebook-Antivirus" src="http://infosec3t.com/wp-content/uploads/2010/03/Facebook-Antivirus.jpg" alt="" width="516" height="398" /></p>
<p>If a Friend looking through the photos then clicks on the app&#8217;s  link, they&#8217;ll see this:</p>
<p><img class="aligncenter size-full wp-image-2034" title="FBAV-approval" src="http://infosec3t.com/wp-content/uploads/2010/03/FBAV-approval.jpg" alt="" width="599" height="248" /></p>
<p>If you have a lot of friends, you might end up with a series of albums like this:</p>
<p style="text-align: center;"><a href="http://infosec3t.com/wp-content/uploads/2010/03/FBAV.jpg"><img class="aligncenter size-full wp-image-2035" title="FBAV" src="http://infosec3t.com/wp-content/uploads/2010/03/FBAV.jpg" alt="" width="582" height="343" /></a></p>
<p>Apart from the wall spamming, another obvious indication that this is a virus itself, is the url:</p>
<p>http://apps.facebook.com/kxetyegpgkxdwfy/</p>
<p>A valid application is not going to have a url with a bunch of jumbled letters at the end.</p>
<p>If you have been tagged in <span style="color: #888888;"> </span>the photo by one of your friends (remember, they did not really do this – the app did automatically), you can remove the tag.</p>
<p>1. Open your photos<br />
2. Click the offending picture<br />
3. Look for your name in the list of people tagged<br />
4. Click the ‘Remove Tag’ link that appears beside your name</p>
<p>The photo will then automatically be removed from your photo list.</p>
<p>Source:</p>
<p><a href="http://www.f-secure.com/weblog/archives/00001920.html">http://www.f-secure.com/weblog/archives/00001920.html</a></p>
<p><a href="http://thefacebookinsider.com/2010/03/warning-facebook-antivirus-will-virally-spam-your-friends/">http://thefacebookinsider.com/2010/03/warning-facebook-antivirus-will-virally-spam-your-friends/</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/03/17/beware-of-fake-facebook-apps/' rel='bookmark' title='Beware of fake Facebook apps'>Beware of fake Facebook apps</a> <small>Facebook is warning users to avoid bogus apps that claim...</small></li>
<li><a href='http://infosec3t.com/2010/02/06/facebook-intros-revamped-home-page-important-new-privacy-setting/' rel='bookmark' title='Facebook intros Revamped Home Page, Important New Privacy Setting'>Facebook intros Revamped Home Page, Important New Privacy Setting</a> <small>On Friday, Facebook  rolled out a new home page and...</small></li>
<li><a href='http://infosec3t.com/2010/01/28/fake-virus-alert-spreads-massively-across-facebook/' rel='bookmark' title='Fake virus alert spreads massively across Facebook'>Fake virus alert spreads massively across Facebook</a> <small>Panda Security has released the following advisory: In the last...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/29/dont-install-fake-facebook-antivirus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

