Facebook likejacking attacks continue with 'Paramore n-a-k-ed photo leaked!'

Clicking onward only brings the Facebook user to a page which, unbeknownst to the victim, has hidden code that executes the action of "liking" the Web page

Facebook users are falling for yet another clickjacking scam that fools them into "liking" a page. This one lure victims with the message "Paramore n-a-k-ed photo leaked," which claims to point to a Web site containing a naked photo of Hayley Williams, lead singer in the rock band Paramore.

But clicking onward only brings the Facebook user to a page which, unbeknownst to the victim, has hidden code that executes the action of "liking" the Web page. That action gets published on the victim's Facebook page and shared with online friends, according to security firm Sophos, which has been tracking this type of attack, which it calls "likejacking."

'Likejacking' exploit fools Facebook users and friends

Sophos earlier detailed other likejacking exploits based on other phrases, such as "The Prom Dress That Got This Girl Suspended from School" and "This man takes a picture of himself EVERY DAY for 8 years!" and more.

Sophos senior technical consultant Graham Cluley says the likejacking attack that attempts to gull users with the message 'Paramore n-a-k-ed photo leaked!' will take victims to a third-party Web site, which displays a message that says: "Click here to continue if you are 18 years of age or above." But don't do it, Cluley says, writing a blog on the topic.

"What the hackers have actually done is very sneaky. They have hidden an invisible button under your mouse, so wherever you click on the website your mouse-press is hijacked. As a consequence, when you click with the mouse you are also secretly clicking on a button which tells Facebook that you 'like' the webpage. This then gets published on your own Facebook page, and shared with your online friends, resulting in the link spreading virally," Cluley writes. It's technically similar to the earlier likejacking exploits in that it makes use of what's called an iFrame exploit.

He notes the same Web site associated with the Paramore likejacking attack is hosting another Web page containing a clickjacking attack related to "teen heart-throb singing sensation Justin Bieber," that claims his phone has been leaked.

Cluley says Facebook should consider altering how 'liking' is executed online. "It's clear that Facebook needs to tighten up the way it handles the 'liking' of external webpages before it is even more widely abused by malicious hackers and spammers."

Cluley speculates that the likejacking exploits recently seen may be a proof-of-concept attack that could lead to more dangerous use of this type of exploit in the future, such as spreading dangerous malware.

Read more about wide area network in Network World's Wide Area Network section.

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags securityclickjackingFacebook

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Ellen Messmer

Network World
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?