The Killer Facebook Application Arrives and it Ain’t Pretty

According to IDG News Serivce, “A team of researchers have built a malicious Facebook” application. We’ve heard this before it and now we’ll here it again. Facebook applications can be used to “dupe large numbers of users into downloading a seemingly harmless application that actually performs a clandestine attack that can cripple a Web site.

Wait, can’t any website do the exact same thing? Yes it can! These researchers came up with a new way of attacking their victims though. As the article revealed:

The researchers developed an application called “Photo of the Day,” which serves up a new National Geographic photo daily. But in the background, every time the application is clicked, it sends a 600 K-byte HTTP request for images to a victim’s Web site.

Those requests, as well as those images, are not seen by someone using Photo of the Day, which the researchers have termed a “Facebot” application. The effect is a flood of traffic to the victim’s Web site, known as a denial-of-service attack.

The application remains listed on Facebook and still hasn’t been shut down. While I’m guessing this application will be shut down within the next few hours it’s interesting to see a known application which is testing vulnerabilities is allowed to run on the platform. Then again, monitoring all of the packets being transferred between the application and the user and still determining a packet is harmful is completely unlikely.

I’m not quite that the vulnerabilities described are unique to social networks. Instead it sounds like the argument is that there are more “vulnerable users” on social networks then any random website. I’m not sure I agree with this argument but I’ll leave you to decide.

  Tags:



Recommended Articles


Inside Social Apps 2012 is Less Than Two Weeks Away

Inside Social Apps, held on February 8-9 in San Francisco, is less than two weeks away. This is the third conference on the future of monetization on social and mobile platforms. Leaders from the industry will share their views on today's most formidable challenges affecting social and mobile apps and games in 2012. Inside Social Apps conferences sell out in advance, so take advantage of early registration pricing. Early bird rates end on February 1, so register today.

No Comments »

No comments yet.

RSS feed for comments on this post. TrackBack URL

Leave a comment

Send us a Tip

tips@allfacebook.com
[Inside Social Apps 2012]
[AllFacebook Stats: Facebook Analytics for Your Business]
[How can Facebook change your business?]

Upcoming Events

Inside Social Apps

February 8-9, 2012 | San Francisco

Inside Social Apps

Developing & monetizing on social & mobile platforms

Social Gaming Summit

23-24 May, 2012 | Berlin

Social Gaming Summit

Where Gaming Meets the Social Web

AllFacebook Marketing Conference

June 28-29, 2012 | San Francisco

AllFacebook Marketing Conference

Your how-to guide for Facebook marketing.