Facebook
Sites such as Facebook could soon become DoS launch pads
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Researchers warn of Facebook malware

Social networking app could be used for DoS runs

Shaun Nichols in San Francisco, vnunet.com 08 Sep 2008
ADVERTISEMENT

A group of Greek security researchers has created a tool to turn Facebook into an attack platform.

The researchers are from the Institute of Computer Science at the Foundation for Research & Technology Hellas, along with a researcher from Singapore's Institute for Infocomm Research.

In a paper entitled Antisocial Networks (PDF) the researchers demonstrated an application that causes Facebook users to unknowingly participate in denial-of-service (DoS) attacks against other sites.

The 'Facebot' tool was disguised as a National Geographic 'picture of the day' application which users install into their Facebook profile page, thus allowing it to access account information and request new photos.

When users access the application to view a new photo, they unwittingly become internet attackers.

Along with the request for a new photo, Facebot sends a series of HTTP requests to an outside target. The multiple requests for each user ultimately add up to 600KB worth of data per click.

With enough users subscribing to the application, Facebook could become the launch pad for major DoS attacks.

Because the applications can be disguised as non-threatening items, users could unwittingly participate in a large-scale attacks.

The researchers noted that Facebot exists only as a proof-of-concept, and that there are no known instances of such a tool being used in the wild. However, they believe that the risk is still very real.

Facebot does not exploit a single vulnerability in Facebook, but instead builds on the core components of social networking services, such as large user bases and open platforms for the exchange of code and content.

"Social networks have some intrinsic properties that make them ideal to be exploited by an adversary," the researchers said in the report.

"All these characteristics give adversaries the opportunity to manipulate massive crowds of internet users and force them to commit antisocial acts against the rest of the internet without their knowledge."

See also:

mobile phone usersLawyers speak of dangers of location monitoring applications  15 Aug 2008
Three quarters of parents snoop on kids' social networks  07 Aug 2008
HackerMalware tactics evolve further  30 Jul 2008
FacebookClaims are invalid, says StudiVZ  21 Jul 2008

All Hacking
Tags: Facebook, Dos-attack, Internet, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities