Wednesday, May 4, 2011

The All-In-One Facebook Scam Report. Read It To Stay Safe.



Share

Update: 05-06-2011
Note: Facebook seems to be prompting users with a Security Check box when trying to share my reports. Do not be alarmed by the prompt. Simply enter the code they ask you to and click the submit button. The report will share after that. It seems to be some type of error currently. Hopefully they fix it soon.

There have been quite a few scams flying around Facebook over the last few days. I have received many reports and questions about them, so I figured I would construct this All-in-One report. The All-In-One report should provide users with a quick way to refer to the various warnings that have already been released.

In general Facebook users should refrain from clicking or following random/un-trusted links on the platform, Even if the links appear to come from trusted friends. Links to Spam, Scams and other malicious elements may appear in your News Feed, Inbox, Chat Window and you may find that you have been invited to strange events offering links as well. Never follow the instructions given on any page that request you Cut/Copy & Paste JavaScript code into your Web Browser while logged into facebook. Doing so will cause you to compromise your Facebook profile, send spam to your friends and may even make you inadvertently install a virus or other malware on your computer. -See Note 2- Also refrain from installing random 3rd party Facebook Applications. Take a few seconds to check any application out before you install it on your Facebook profile. Please be sure to update all of your computers security software as well.

The scam, spam and virus threats vary on Facebook at the moment. Users should avoid any messages of the following types:
  • Messages offering Videos or Photographs of Osama or Usama bin Laden's death or related news.
  • Messages asking you to help someone by clicking some random link on their profile.
  • Messages offering to show you how you will look in the future. (20 Years or whatever.)
  • Messages offering to show you how your baby will look.
  • Messages offering to show Profile Stalkers, Creepers, Peekers, Spies or views.
  • Messages claiming facebook is closing or needs you to verify your account before a specified date.
  • Messages claiming to give you free makeup, airline tickets, iPhones, iPods or iPads.
  • Messages claiming to show you a shocking video or photo (celebrity or other). Justin Bieber or Lady Gaga may be the main bait.
  • Messages claiming to give you free game currency or facebook credits.
  • Messages claiming to give you a paid for game item for free.
  • Status Messages offering virus warnings, amber alerts or hacker warnings that offer no real details or official proof. They just urge you to repost the sketchy information in them. 

Note 1: If you run into any "New" scams, please report them to Facebook first by Marking The Messages As Spam, then take a few seconds to report them to me, ( Right Here ) or ( Right Here ), if you would like to.

Note 2:  Pasting JavaScript Codes - Why You Really Shouldn't Do It. Via - Symantec's Blog
Once a user copies and pastes the JavaScript code, then hits the enter key, it misuses the logged-in user session to enumerate the their friends list and start its shenanigans. Depending on how it has been configured by the attacker, the script will post a new bait message to the user’s wall, send chat messages to their friends, tag you in post messages or images, or even create an event and send an invitation to all your friends. Of course, as always the attack is easy configurable through a toolkit the scam artist uses and may be different for each new scam. Since the script runs in the context of Facebook, while you are logged into Facebook, it can do a lot with your profile. It can honestly do nearly everything you could do yourself. So please refrain for pasting these types of codes into your web browsers. You are not going to like what will eventually happen if you do not.

Resources: Various Alerts and Scam Reports.

Adware Alert : Amazing Web Cam childbirth video (05-06-2011) Active
http://www.thebulldogestate.com/2011/05/adware-alert-amazing-web-cam-childbirth.html

Facebook Spam Spreads Through Multiple Features (05-06-2011) Active
http://blog.trendmicro.com/facebook-spam-spreads-through-multiple-features/
I dub thee Admin of Page [x]. Arise and Get your Scam (05-06-2011) Active
http://www.malwarecity.com/blog/i-dub-thee-admin-of-page-x-arise-and-get-your-scam-1069.html
Alert: Avoid Need help please.. :) can you please click messages. (05-05-11) -Still Active
http://www.thebulldogestate.com/2011/05/alert-chat-spamming-like-jacking-links.html

FarmVille Scam Warning: Avoid The Fake Rainbow Cow Message. (05-05-11) -Still Active
http://scamsniper.blogspot.com/2011/05/farmville-scam-warning-avoid-fake.html

The BLOODIEST Fight EVER - BANNED FROM TV (05-03-11) -Still Active

Manual Script Scams on Facebook Generating Event Invitations (05-04-11) -Still Active
http://www.symantec.com/connect/blogs/manual-script-scams-facebook-generating-event-invitations

Bin Laden's death photographs or videos, Are they real or not? -Graphic Photograph Included. Updated With Facebook Scams and Virus Warnings: (05-02-11) -Still Active- High Alert
http://scamsniper.blogspot.com/2011/05/osama-bin-ladens-death-photograph-is-it.html

Warning: 25 Profile Spy Scams To Avoid. Updated Regularly (04-09-11) -Still Active
http://scamsniper.blogspot.com/2011/04/warning-15-currently-active-profile-spy.html

Avoid ALL "Verify Your Facebook Account By May 5th" messages. (05-02-11) -Still Active
http://www.facebook.com/photo.php?fbid=10150167002051787&set=a.336226391786.160140.329801526786&type=1&comments

Facebook Deleting all Profiles at MAY 8th which are not verified (05-02-11) -Still Active

[SCAM ALERT] 2 FREE Southwest Airline Tickets! (05-01-11) -Still Active

Linda Smith / Jason Lee Facebook virus hoax spreads quickly (05-04-11) -Still Active

Trying To See a Father walk in on his Daughter Will Get You Jacked. (05-01-11) -Sleeping
http://scamsniper.blogspot.com/2011/05/click-jack-alert-trying-to-see-father.html

*SCAM ALERT* - Avoid ALL "Guy gets Pantsed Live" or "Justin Bieber gets pantsed by fans during performance" messages. (05-01-11) -Sleeping
http://www.facebook.com/photo.php?fbid=10150165947376787&set=a.336226391786.160140.329801526786&type=1&comments

[SCAM ALERT] See how your baby will look like? (05-04-11) -Sleeping




About Black Knight

I am a computer repair technician with over 15 years experience and have been computer security and information privacy enthusiast for the last 4 years. I've helped literally thousands of individuals fix their issues by offering help through various blogs and Facebook pages. I like teaching myself and others new things, and believe in freely sharing knowledge.

4 comments:

  1. This is GREAT!

    Suggestion: In your Description on the URL links of you posting always include the date.

    ReplyDelete
  2. Thanks for the suggestion Fred and will do. Just to let you know, the Resources links are all current warnings, nothing older then 2 days.

    ReplyDelete
  3. Correction: There are a few older reports there. They are included because the threat still exist and has been reported to me. :)

    ReplyDelete
  4. I wish I had seen your site last week. I did cut and past javascript. All my friend received chat invites and were upset with me over it. What a bad, bad thing. Now I know, right!

    ReplyDelete