Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

10/2/2009
01:25 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Beware Hijacked Social Networking Accounts, FBI Warns

Social networking sites are becoming a more popular attack vector for cybercriminals because people trust those they believe to be friends.

Think twice before wiring money to help a Facebook friend who claims to be in trouble in a foreign country.

Marking the commencement of National Cybersecurity Awareness Month, the Federal Bureau of Investigation (FBI) on Thursday warned that there's been an increase in hijacked social networking accounts and that cybercriminals are using these accounts to defraud victims' friends.

Since 2006, there have been 3,200 reports of account hijackings, according to the Internet Crime Complaint Center (IC3).

Such scams often begin with spam messages.

"When opened, the spam allows the cyber intruders to steal passwords for any account on the computer, including social networking sites," the FBI said. "The thieves then change the user's passwords and eventually send out distress messages claiming they are in some sort of legal or medical peril and requesting money from their social networking contacts."

Facebook's security blog includes a transcript posted in August of a chat conversation in which this very scam is played out.

"Pretending to be Derek's friend Jill, the scammer tells Derek that she was mugged at gunpoint in London, and that she needs him to wire her $890 immediately," Facebook explains. "Derek becomes more and more suspicious as the conversation progresses and ultimately realizes that the person he's talking to isn't his friend, and that the story he's being told is a lie."

Another common scam, the FBI said, involves phishing spam that presents a fake notice about some issue requiring attention, such as a terms of service violation, account expiration, or unexplained account activity. Messages of this sort often seek to prompt recipients to click on a link that leads to a malicious site and to provide personal information or account details.

The reason that cybercriminals seek to abuse social networking accounts is that messages from friends have an appearance of legitimacy.

As if to underscore the FBI's concern, Roger Thompson, chief of research at AVG Technologies, reported in a blog post on Thursday that his company had detected a series of identical Facebook profiles, differentiated only by profile names, set up to distribute fake anti-virus software through a link purporting to be a home video.

The FBI advises: that users check their privacy settings on social sites to make sure they're not exposing too much information; being selective about friends on social sites; disabling unused sharing options; being careful about links posted to social sites; and reviewing the security settings and procedures at social sites.


InformationWeek has published an in-depth report on smartphone security. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5162
PUBLISHED: 2020-02-25
An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as t...
CVE-2019-5165
PUBLISHED: 2020-02-25
An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web authentication. An attacker ...
CVE-2020-9383
PUBLISHED: 2020-02-25
An issue was discovered in the Linux kernel through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2.
CVE-2019-5136
PUBLISHED: 2020-02-25
An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands ...
CVE-2019-5137
PUBLISHED: 2020-02-25
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.