Advertisement
Promo

Security threats Toolkit

Facebook fends off two days of phishing attacks

Elinor Mills CNET News

Published: 01 May 2009 09:08 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Facebook stopped a phishing attack on Thursday, its second day in a row of dealing with a worm on the site that lures people to a fake Facebook page and prompts them to log in.

Unsuspecting Facebook users get a message from a friend urging them to "check this out" and including a link to a web page that appears to be a Facebook log-in page, but it is a fake site that steals their information when they type in their username and password. The worm also sends a copy of the message to the infected Facebook member's contacts.

In the latest attack, the web address was 'FBStarter.com'. In Wednesday's attack, the address was 'BAction.net'.

The attacks were stopped within a few hours in each case, said Facebook spokesman Barry Schnitt. He said it was too early to say whether the two phishing attacks are related. "We are investigating," Schnitt said.

Once Facebook learns of a phishing attack, either by members notifying the company or employees noticing that a URL is being distributed to a lot of people, the company deletes the URL from members' pages, blocks fresh postings, and removes the redirect to the URL that appears in email messages, Schnitt said.

Facebook also goes in and resets the passwords of member accounts that had been used to distribute the spam, he said.

The company also alerts anti-fraud partner MarkMonitor, which passes the phishing URL on to the major browsers to block it and contacts ISPs to take the site down, according to Schnitt.

To protect against phishing scams, Facebook users should make sure that the URL they are visiting says 'www.facebook.com'. If it does not use that domain, it is likely to be spam. Also, members who are already logged in to Facebook will not be asked to log in again.

"People should have a healthy dose of suspicion, and ask themselves: 'Why did I get logged out?'," Schnitt said. "If something looks a little strange you should check the address bar."

Facebook users who think they have been affected by the scam should change their passwords and review their Facebook stream for any unauthorised changes. If they use their Facebook password for other sites, they should change those passwords as well. And if they are using their Facebook authentication to log in to any other sites, they should check for any unauthorised changes on those sites.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
60 out of 62 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters