Top Ad unit 728 × 90

Facebook self-xss scam tricks users into hacking themselves


Scammers have again targeted more than one billion active users of the popular social networking giant Facebook, to infect as many victims as possible. Not by serving fake post, neither by providing malicious video link, instead this time scammers have used a new way of tricking Facebook users into injecting or placing malicious JavaScript or client-side code into their web browsers.

The latest Facebook scam promises to give people the ability to hack into anyone's account. But follow the instructions and you'll only end up hacking your own page, via a trick called Self-XSS, thus making yourself vulnerable to new scam campaigns. Well, don't dish it out if you can't take it, right?


The scam appears as either an email or a Facebook post on your Timeline purportedly from a friend of the victim. "Hack any Facebook account following three steps," the scam promises. It then instructs readers to open Facebook in a web browser and go to the Facebook page of the person they want to hack. Then right-click anywhere on the page and from the popup menu select Inspect Element. This brings up an HTML editor at the bottom half of your Web browser.

In this editor, the scam instructs readers to copy-paste a string of code. But, unsurprisingly, the code does not do what the scammers claim it does. Rather, this code grants the scammers access to your own account.

The scammers can now access all of the users' data, including photos and messages, and can post about the scam on their Wall, thereby luring more potential victims.

This scam makes use of the Self-XSS (cross-site scripting), which is a vulnerability with web browsers, not Facebook. In fact, Self-XSS is among the social networking titan's list of security threats. However, there is no security patch released by the company to fix this at its own end, just a warning to not post such codes into the HTML editor.
Facebook self-xss scam tricks users into hacking themselves Reviewed by Ankit Kumar Titoriya on 10:02 Rating: 5

No comments:

All Rights Reserved by gaklakl © 2014 - 2015

Contact Form

Name

Email *

Message *

Powered by Blogger.