Showing posts with label Clickjacking. Show all posts
Showing posts with label Clickjacking. Show all posts

BEWARE OF THE NEW FACEBOOK SPAM | [VIDEO] Yeahh!! It happens on Live Television!



Lately, a number of Spams have hit facebook.  No matter how much secure measures facebook sets, the spammers always find their way through. Lately, i saw a new type of facebook spam continuously being posted on my timeline ( its no longer a wall when it has been updated to timeline interface). The message went like... " [VIDEO] Yeahh!! It happens on Live Television!" blaa blaah blah....... Well i knew that it was just another facebook spam. "If you receive such a link, just remove it manually from your news feed, DON'T click on the link".


Earlier, a friend of mine messaged me, asking on how he can stop the spam from spreading to all his friends timelines and walls, since it carried his name with it and the target name of his friends. In the end, it looked as if he was the one who really recommended the link to his friends.

Therefore, i decided to write this article on this latest facebook spam, and how you can stop it from spreading. First of all, these types of  spams are all examples of ClickJacking attacks, which i wrote about in my earlier article on how they are carried out.


How This Spam Malware Infects Facebook User
  • You will receive a notification that a friend has shared a link, on your timeline (wall).
  • when you click on the notification, it takes you to a page that is similar to the one below

  • The Spam message is "[VIDEO] Yeahh!! It happens on Live Television!"
  • This video title then defeats your curiosity and finally you decide to click on the link to watch the video.
  • Then suddenly, you will be asked to install a plugin (fake plugin) in order to watch the video. similar to the one below.


  • Just a single click on "install plugin" and its Game Over! The Spam message then spreads to all your friends timelines (walls). It will continue spamming your friend's walls for as long as you remain infected by this malware... :P
How to Disinfect Yourself from the Spam

Since the aim of this spam is to trick you into installing a fake plugin that performs malware functions onto your browser, therefore you need to remove that plugin first.

1. From your Internet's browser settings, go to the addons or Extension settings and remove or uninstall any addon with the name similar to the "Youtube Extension"

For example, for firefox users, go to your addon settings or press CTRL+SHIFT+A 


Now remove any addon with the name or icon similar to youtube extension and restart your browser. Do the same for any other browser.



2. Use Bitdefender Safego Antiscam protection. Bitdefender Safego is a facebook application and Malware Scanner that will scan your news feed and keep you away from scams like this.


3. Clear any saved browser cookies and caches on your computer. You can use eCleaner ,. and make sure to do a full scan on your computer with updated Antivirus because some of these malware tend to spread to the rest of your computer.

And lastly, NEVER click on such links that always punch your curiosity, such as;
  • Shows her boobs on National TV
  • Bedroom Adventures.. Amazing
  • Lol Check this video out
  • Look at What she did on Live TV
  • You will hate Rhihana after watching this video
  • Breaking news Lady Gaga found dead in hotel room [VIDEO]
  • OMG! Look at this 6 year old.... [shocking]
The list is Endless, and especially on this festive season, expect more scams and spamming to come all in the name of "Christmas". Spammers always take advantage of such events. have the basic knowledge and you will know how to kick them out.  :xD

Read More | comments

WHAT IS CLICKJACKING ATTACK? | HOW TO PROTECT YOURSELF


Recently, there has been a rash of clickjacks that led to the spread of violent and pornographic images across Facebook.According to a statement from Facebook, the attack used bait links to trick users into launching scripts that cut and pasted Javascript code into the URL, causing them to unknowingly share this offencive content. Facebook did take some steps to shut down the accounts used in the attack, and said that it reduced their frequency. however, facebook did not indicate that the attack was over.

Clickjacking is the most common technique used by the bad boys (hackers) in such attacks. In this attack, the attacker Tricks the user into revealing confidential information and other account details required to spread the attack further. So really, What is clickjacking?

Clickjacking, also known as "UI Redressing" is a Malicious script which takes over the links displayed in the Internet browser for various web pages. In such a case, the user is taken to a site which is unintended when he tries to lick on that link. Take a close look at the image below


From the above illustration, In other words, clickjacking is simply an embedded script or code which can trigger a button that appears to perform another function, without the user’s knowledge.

Recently, a new clickjacking tool was disclosed that allowed clickjackers to hijack your computer's camera (webcam) using adobe flash. This allows them to spy on the victim by taking pictures, streaming videos e.t.c secretly via Internet connection.

So if you are a cyberholic and your computer has a webcam, Your best defence is to place a piece of tape strategically over your camera, with this analog solution, you will never go wrong lol .
And not only the victim's webcam, adobe flash also enables clickjackers to gain access of the user’s microphone thereby gaining access to audio streaming.

In a little detail, when a user (victim) visits an unknown web page hooked with a clickjacker script, the target application waits invisibly and is loaded while it floats an invisible "allow" button on the victim's browser screen. For example, an "invisible allow" button can be embedded behind a "visible login" button. Therefore, a single click on the login button triggers the allow function that in return gives full permission to run the target application, hence you have have been clickjacked man!

Clickjacking can be fatal, it can clear all your personal data, from your computer, social security data, credit card numbers and other sensitive bank information. The malicious script is also capable of installing a number of  unwanted software, adware, spyware or even virus onto the victim's computer without his knowledge.

Below are the images of a few famous clickjacking Scams the web

1. IDEO SHOCK - Hurricane Irene New York kills All


2. OMG ..Look what this 6 year old found in her happy meal From McDonalds! [shocking]


3. Cheryl Cole Exposed Paparazzi Photos!


4. Breaking News Lady Gaga Found dead in Hotel room [video]


How to protect yourself from Clickjacking?

As you can see from the above images, they look as original as they can be, apparently one way to combat this would be by using a text-based browser. But that wouldn't be the case in this modern age of technology :D 
So how do you protect yourself?
Its simple, Simply dissable scripting on your browser . This can be done with the help of browser addons Such NoScript for Mozilla Firefox, NotScript for Google chrome browser e.t.c... These will block any Scripts like javascript codes from executing on your browser without your approval. So you can only whitelist trusted websites and web pages on which you want the scripts to run.

Disable scripting addon links

1. Mozilla Firefox  - Install NoScript  (Click here )
2. Google Chrome - Install NotScript (Click here )
3. Opera Browser - Install NotScript (Click here )

The above addons are the best protection you can get at the moment. Not only will they protect you against clickjacking, they'll also protect you from another Internet scam known as Tab Napping or Advanced phishing.

Stay alert,..!!! be smart :D:D:D
Read More | comments

Total Pageviews

Free Automatic Backlink Free Auto Backlink
japanese instant free backlink
Free Automatic Backlink Service Malaysia Free Backlink ServicesFree Promotion LinkFree Smart Automatic BacklinkMAJLIS LINK: Do Follow BacklinkLink Portal Teks TVAutoBacklinkGratisjapanese instant free backlink Free Plugboard Link Banner Button

 
Copyright © 2011. Ethical Hacking Unleashed . All Rights Reserved.
Company Info | Contact Us | Privacy policy | Term of use | Widget | Advertise with Us | Site map
Template modify by Creating Website