Saturday, January 29, 2011

Friday, January 28, 2011

Warning: Emails About Facebook's Online Splash Promotions are a scam.



Share

Quite a few users have reported receiving the below message in their facebook inbox today. One person in particular complained that after receiving the message, their computer froze. I can not say if that was just a coincidence or an effect of opening the message. In any event the message is spam, should not be open and should be deleted.

This is a scam designed to get your private information, your money, or both. 

First: There are no such things as:
  • Facebook online splash promo selected from The Middle East region or any other region.
  • Digital Random Internet Processing Service Asia Pacific (D.R.I.P.S).
Secondly:
  • Facebook will never give you interests generated from advertising and copyrights as a reward or anything else. 
  • Why would the facebook team contact you from or ask you to contact them at a Gmail or Yahoo email address.
Thirdly:
  • The word is "Prize"
If you see the message below in your facebook inbox, Report the message as spam, then delete the message. If this message was sent to you by a person in your friends list, I suggest you delete and block that person as well.

Example Inbox Message (Click to Enlarge)

----Example Message Text Type 1----
28 January at 20:35 Report
Congratulations: "Facebook User",

You have been selected as one (1) of (15) winners in this months Facebook online splash promo selected from The Middle East region by our internet processing unit. Our fifteen (15) winners have been selected from five continents currently connected to the Facebook network Bangkok Thailand. Award Attached to ticket number (5647600545189) and ballot number (BT: 12052006/20).

Your User name as the 5th beneficiary in this promo was chosen at random by our Digital Random Internet Processing Service Asia Pacific (D.R.I.P.S) and your reward is coming from the interests generated from advertising and copyrights from the Facebook network Thailand.

Congratulations once again from Facebook, You are entitled to a surprise package worth the sum of $750,000. ( Seven hundred and fifty thousand dollars Only). Contact Our THAILAND DISTRICT Online Coordinator directly with the below information;

Name: Mr. Richard Morgan
Email: fbonlinelottocordinator@yahoo.com.hk

FULL NAME: .............................
CONTACT ADDRESS/NOT Po BOX:.............
PHONE NUMBER:...........................
COUNTRY/NATIONALITY:....................
YOUR EMAIL ADDRESS:.....................
TICKET NUMBER :.........................
BALLOT NUMBER:..........................

Do not disclose this to any one on till you claim your price for security reasons.we have had cases where the last winners complain of someone else claiming their prices.

Fiduciary Agent: Mrs. Laura Macy
E-mail: facebookpromo2011@gmail.com
----End Example Message Text Type 1----


Wednesday, January 26, 2011

Mark Zuckerberg's fan page hack has finally been confirmed by facebook.



Share

Mark Zuckerberg's fan page hack has been confirmed by facebook. Facebook explains that a bug, specifically in an API (application programming interface) that allows publishing functionality on the site is to blame for the incident. They also stated that a hand full of other pages were affected, but would not state which ones or if this bug was responsible for hack earlier this week of French President Nicolas Sarkozy's Facebook page.

Read more of the CNET Report Here: 
Facebook blames bug for Zuckerberg page hack
http://news.cnet.com/8301-27080_3-20029630-245.html#ixzz1CAibNl8T

I'm assuming that this bug could also explains why many users saw a person named Ekşın Man appear in their news feeds yesterday and the appearance of a person named Roy Castillo today. Digitizor.com has posted information stating that the Roy Castillo appearance was part of an XSS hack. I would guess that this hack exploited the bug facebook has confirmed. Below is a picture of the Ekşın Man post I saw in my feed yesterday, as well as a picture and a link to the Digitizor.com report on Roy Castillo for more info..

Example (Ekşın Man post)

Example (Roy Castillo post)- Property Of Digitizor.com
Via Digitizor.com
Who Is Roy Castillo And Why Is He All Over Facebook?



Tuesday, January 25, 2011

Survey Scam: Free MAC Makeup Kit.



Share

The Scam:
WOW i just got some free MAC MAKEUP from  +[Link]

Summary:
Facebook users may notice some of their friends posting a message with the words "similar to the one shown aboveand a attached link. The message is not posted by your friends, but by a Rogue app they have been tricked into installing, under the impression that they are going to get some free MAC cosmetics.. After being re-directed to an external website, The Rogue application "Makeup Samples", which victims are prompted to install, does nothing more than Spam your wall, without your knowledge, with aforementioned bogus message and links once you "Allow or Install" it on your facebook profile. The end game is you must fill out surveys or download products to get the free samples that don't exist. This is a Survey ScamDO NOT CLICK THE LINKS IN THE MESSAGES OR INSTALL THIS APP IF YOU SEE IT POSTED IN YOUR NEWS FEED BY A FRIEND

Scam Type: Rogue App, Survey Scam, Airline Tickets

Block App Links - ( You can use this to block the facebook app from your profile. )

The Break Down
Facebook users may notice some of their friends posting a message similar to the example below. DO NOT CLICK THE LINK given in the post. 

Example

If you take the bait and click on the link, you will be directed to the site "fbmacsamples.info", which is shown below.

Example

While you are taking the time to read the page you will notice the page automatically accepts the Term presented to you and then reloads to look like the screen shot below.

Example

At this point you are told to select which makeup sample kit you would like to receive. If you continue by clicking on one of the samples pictures, the page will then display that you need to click the button to join Mac on facebook. Clicking on the button will then open a pop up with a facebook app request for permission screen in it..  See example..

Example (Button Required To Click)

Example (Button Required To Click)


You are asked to give an application named "Makeup Samples" the requested permissions as you see above. It's asking for quite a lot of access to your profile. The important thing here is that you stop and look at these application screens. Do not blindly allow applications that you have not personally reviewed and you know nothing about, have this kind of access to your profile. This particular set of "Permissions" will:
  1. Allow this app access to your basic profile information.
  2. Give it the ability to post to your wall without asking.
This application is requesting all of these permissions because once you click allow, the following message will be posted to your wall without your knowledge and you haven't even been shown what was promised in the original message.

Example

While your friends see the above messages pop up in their news feeds, (Spamming Them), you are shown  that you must do a short survey to continue. Sadly these are nothing more ploys to get you to download a product or do a Survey for which a scammer will be paid. You will not receive any makeup from this scam.  It is advised that if you see this scam posted in your feed, do not click any of the links. See example.

Example (Click To Enlarge)


It is important that you never hand over any personal information, such as: email addresses, cell number, name, home address or credit card numbers, to these types of scams. If you do, you are simply setting yourself up to be spammed or worst. Identity theft is big business and handing over some of the info these bogus surveys ask for, will make you a victim of that business. If you have made the mistake of handing over a credit card number, you should call your bank or credit provider as soon as possible to have them remove or dispute the charges that have or maybe made to the card. If you've given your cell number to any of these types of Scams, it is important that you call your cell carrier ASAP to have any charges you may receive stopped. If you begin to receive unsolicited phone calls, you should take note of the calls, record names and numbers, then report the calls to the FCC or other proper authorities..

Read here to learn how to avoid these types of scams on facebook.

Facebook Spam

Damage Control For those who have fell victim. )
If you have fell victim to any of these scams, you need to clean up your facebook profile immediately by removing the posts they made to your wall and then removing plus blocking the rogue application that you may have install to your facebook. If you've downloaded and installed any programs to your computer, it is advised that you run a full virus scan immediately.

Stay Virus Free