Skip to Content

Free TUAW iPhone app -- try it now!
AOL Tech

Filed under: Security, Social Software, web 2.0

Bad guys now launching attacks through hacked Facebook apps

Social networking sites like Twitter and Facebook can already be dangerous places. Things like short links and bogus messages from friends with compromised accounts put unsuspecting and under-prepared users at risk.

Now, AVG's security researchers have discovered a new threat on Facebook. For the first time, they've found hacked Facebook apps. According to AVG, the apps are being used to launch drive-by attacks which target vulnerabilities in Adobe Reader and Adobe Flash. AVG reports finding seven hacked apps, but they admit there could well be more.

First things first: if you're not running up to date versions of either of those, download them right now. Here's the link to Flash and here's one for Reader. Using anything but the most current version could leave you open to attack.

The attack works like this. Visit the Facebook page for any of the hacked apps and click to install. Instead of the normal process, the page will try to push a poisoned PDF document to your machine. Once open, the infected PDF infects your system with a bogus antivirus application - which are often notoriously difficult to remove.

I've mentioned fake antivirus programs like these before on Download Squad. If you've been infected, you can try the tools listed on this post to clean up your system.

To keep from getting infected in the first place, make sure you:
  • have a good antivirus program installed and that it is fully updated
  • update browser plugins like Java, Flash, and Adobe Reader as soon as you are prompted to do so
  • install any critical Windows updates that are available
  • check comments on new apps before you install - others may have already been infected and left a post on the wall!
jobs & resumes
Sr Designer

AOL Advertising - New York, NY (7 hours ago)

See More Relevant Jobs ›

Reader Comments (Page 1 of 1)

Add your comments

Please keep your comments relevant to this blog entry. Email addresses are never displayed, but they are required to confirm your comments.

When you enter your name and email address, you'll be sent a link to confirm your comment, and a password. To leave another comment, just use that password.

To create a live link, simply type the URL (including http://) or email address and we will make it a live link for you. You can put up to 3 URLs in your comments. Line breaks and paragraphs are automatically converted — no need to use <p> or <br /> tags.

Featured Time Waster

The Atari classics are back and free to play! Asteroids, Lunar Lander and MORE!

digg_url = 'http://www.downloadsquad.com/2009/11/25/the-atari-classics-are-back-and-free-to-play-asteroids-lunar-l/'; Believe it or not, Atari have just released a bunch of old games on their own website. These aren't clones, these aren't even 'loving interpretations' -- these are the real thing, remade by Atari themselves. This comes as part of a re-launch for the Atari website which includes an online store. I warn you, if you read on, this might turn into more than just a mere ten-minute time-waster. ...

View more Time Wasters

Featured Galleries

Defective by Design, London: Protest Pictures
Livescribe Store
Microsoft Security Essentials
Chromium Pre-Alpha on CrunchBang Linux
Safari 4 Beta
10 Firefox themes that don't suck
IE8 RC1
Download Squad at the Crunchies After-Party
Download Squad at the Crunchies
WordPress 2.7
Cooking Mama: Mama Kills Animals
Windows 7 Hands On
Comodo Internet Security
Android First-look: Amazon.com MP3 Store
Android First-look: Twitroid
Google Reader Android
Android Hands-On
Twine 1.0
Photoshop Express Beta
Mozilla Birthday Cake
Palm stuff

 


Follow us on Twitter!

Flickr Pool

www.flickr.com

More Tech Coverage