Beware of Facebook 'Like' Hijackers

An Internet security firm warns that the Facebook 'Like' button could be used to hijack your web browser.

Source: Getty Images

The "Open Graph", introduced by Facebook CEO Mark Zuckerberg at Facebook's f8 Developer Conference on April 21, is being used by hackers to drive traffic to sites with fraudulent ads, say security experts at Panda Labs.

Be careful what you click on.  Security researchers have found that a growing number of online scams are hijacking the Facebook "Like" option for fraud and profit.

The buttons aren't within Facebook itself, but use the same Facebook technology now used by many sites to integrate with the social networking site to trick them into unknowingly spamming their Facebook friends with messages. The technique, called "clickjacking", is a well-known one. But the introduction of Facebook's "Open Graph" functionality has led to a proliferation of clickjack attacks that use Facebook-related themes, according to Panda Labs.

By disguising the link as something else, Facebook users visiting a site they've been lured to—often with a message that looks like it's from a Facebook game, such as Farmville—are tricked into "liking" a page.  They may not even realize that they are that they are sending a recommendation message about the site to all of their friends in the process, with text that they didn't write.  Cyber-criminals can make money from this by using "pay-per-click" systems—advertising networks that pay affiliates for delivering web traffic to them—and from other offers and ads presented on the pages that users are lured to by the messages.

"Cyber-criminals can make money just by tricking you into visiting a Web page with ads," said Luis Corrons, Technical Director of PandaLabs. "Or worse still, they can spread malware and infect you. This possibility has not yet been exploited, but it would be relatively easy and effective to do it."

So, the next time you find a message on your wall from a Facebook friend with a message that sounds out of character, urging you to click on it now, be careful. It could be your friend has fallen into a trap and is unintentionally pulling you in. Of course, you might say Facebook itself is a trap your friends pull you into...

Share Your Thoughts
For your protection, ensure that no personally identifiable information (like full name or email address) is submitted in your comment.

CAPTCHA
This tests that you are really a person and not a computer.
Image CAPTCHA
Enter the characters shown in the image.
Your Privacy
Trust is a cornerstone of our corporate mission, and the success of our business depends on it. P&G is committed to maintaining your trust by protecting personal information we collect about you, our consumers.
Anonymous | Mar 1, 2011
I love FB. I have been reunited with several friends from my high school days. You just have to be aware and not accept "friends" request from someone you don't know or can't be vouched for.
Anonymous | Jun 21, 2010
This is another reason not to join Facebook. Most of the things people post are not interesting & just a waste of time for me.
Sean Gallagher | Jun 21, 2010

Facebook has its pluses and minuses, to be sure. But this is really no different, honestly, from the things that come in your e-mail inbox.  

follow us
Subscribe to Newsletters
X
About Life Goes Strong Contributors
Newsletter Sign Up Friends
Newsletter Unsubscribe Contact Us
Mobile App Sitemap