| 01 |
| Oct |
Article from Rik Ferguson
Filed under: Hacking,Web 2.0,spam | RSS 2.0 | TB | Tags: compromise, Facebook, hacked, spam, web | 34 Comments
UPDATE: I should make clear that whilst Facebook believe this attack to be related to earlier account phishing activity, more than one victim has assured me that they have not logged into facebook for some while and are certain they have not fallen for a phishing scam. It is certainly true that code has been published on more than one site that uses the Facebook mobile portal to push status updates to a facebook profile.
_____________________________________________________________________________________
A few people have contacted me over the last few days, concerned about spam status messages that were being posted on their Facebook accounts.
The Messages advertise a supposed weight-loss URL (colonrevi.com) which was earning through an affiliate scheme. That URL has already been suspended for abuse, but at the time of the attack it redirected visitors to cleancoloncleanse.com, a site peddling a spurious dietary aid, CleanseProX. I think their own disclaimer at the bottom of the page backs up my use of the word spurious.
The site employs many tricks familiar to fake pharmaceutical scams and rogue AV alike, wildly exaggerated claims of effectiveness, attempts at credibility by association with unrelated content (this site was showing a CBS News video entitled “Conquering colon cancer”) and the unlinked images intended to prove the security of the product or service.
One interesting addition to this was the use of a fake real-time chat window that pops up when you try to navigate away from the site. The window masquerades as a real person responding to concerns and offering half-price shipping to get your order but is in reality a very poorly disguised automated script. In this case it is programmed to respond to words like “scam”, “con” and “real” to assure the victim that this of course is not a scam and that they are talking to a real person, when the reverse is clearly the case. They didn’t have too much to say when I asked them about the compromised Facebook profiles…
You can see from the screen shot that the service is provided by a company called Intellichat, who are very clear on their website that they provide scripted responses rather than live chat. You have to wonder though why they are willing to script responses which are blatant falsehoods, such as the below.
CleanseProX is promoted by a company called Teloxys Technologies Limited, a quick Google search reveals that they are also connected with products such as TrimBerryAcai, CleanseHerbal, Naturacai and Resveratin(an “anti-aging” pill)… CleanseProX doesn’t appear to have too many satisified customers either (yes, people do actually fall for this)
I have been talking to the good folk over at Facebook about this latest account hijacking activity and they think that it is the result of a previous credential phishing attack. The spam updates in this particular attack so far all appear to originate from “Mobile Web“. This does not mean that scammers are abusing your profile via SMS as some victims have feared, only that they are using m.facebook.com (the portal designed for mobile users) to send their spam. SMS updates would show up as origintating from “Mobile texts“. So if you have fallen victim to this, you should change your passwordimmediately. Facebook users should keep an eye on the Facebook Security blog for updates on the latest threats they are seeing.
| Colon Cleansing Spam Running Through Facebook | GeekStream Gadgets: Friday, 2. October 2009 um 12:05 pm |
|
|
[...] to the ingenuity and creativity of the shadowy con-artists. According to the Counter Measures blog, a new scam has emerged, which may be connected to previous schemes, incorporating hacked accounts, new phishing [...] |
|
| Colon Cleansing Spam Running Through Facebook | Everything's Social: Friday, 2. October 2009 um 1:16 pm |
|
|
[...] to the ingenuity and creativity of the shadowy con-artists. According to the Counter Measures blog, a new scam has emerged, which may be connected to previous schemes, incorporating hacked accounts, new phishing [...] |
|
| Carus: Friday, 2. October 2009 um 4:15 pm |
|
|
How do i protect myself from this? it just happened to me… |
|
| Wow: Friday, 2. October 2009 um 10:23 pm |
|
|
Wow Cade you are the biggest idiot i’ve seen in a long time. Morons like you are the reason we have ot deal with spammers today. |
|
| codywohlers: Saturday, 3. October 2009 um 1:28 am |
|
|
I can confirm this happened to my facebook account for purgecolon.net |
|
| Help! Virus via facebook! - BlackBerry Forums at CrackBerry.com: Sunday, 4. October 2009 um 5:59 am |
|
|
[...] [...] |
|
| Kevin: Sunday, 4. October 2009 um 6:39 am |
|
|
As of yesterday, there is a variant which is ExpressColon[dot]net. |
|
| TYK: Sunday, 4. October 2009 um 10:39 am |
|
|
It is kind of irritating to have your facebook status updated without our knowledge. If you are facing the same problem, you may want to take a look at the following blog about purgecolon.net with some steps that we can take to reduce future risks. |
|
| Terry Ogaki.com» Facebook Status/Wall Hack Making the Rounds: Monday, 5. October 2009 um 4:54 am |
|
|
[...] users, including several of my friends, have recently been caught off-guard by strange Status updates and Wall posts, many of them related to weight-loss plans, colon-cleansing products, and other website/product [...] |
|
| Anon: Monday, 5. October 2009 um 6:34 am |
|
|
Same think happened here… Two status updates in about 3 days. I used facebook on my HTC Hero (Android), didn’t happen before that |
|
| dee: Monday, 5. October 2009 um 1:27 pm |
|
|
i wen to this website filled in the form and master card detais, but the there was one box i did not fill it was coz i did not know what it meant it was some sort of code just after the master card details, so am i safe ? |
|
| dee: Monday, 5. October 2009 um 1:35 pm |
|
|
am i safe? thers a box i did not fill , it is a box just after the master card number and code |
|
| sebish: Monday, 5. October 2009 um 9:46 pm |
|
|
I’m getting the same thing from my phone, it seem to pair up with when I installed a custom WebMo Distribution (From XDA Developers) I put on to my phone. |
|
| Nida: Tuesday, 6. October 2009 um 8:20 pm |
|
|
My facebook status got updated by something similar (PurgeColon.net). Changed my password, but how can we prevent this from happening again? |
|
| seperlinky: Wednesday, 7. October 2009 um 7:28 am |
|
|
Now it says something like -> Remember to clean your colon out :) facebookhealth4.com |
|
| Facebook Status/Wall Hack Making the Rounds: Tuesday, 27. October 2009 um 1:59 pm |
|
|
[...] users, including several of my friends, have recently been caught off-guard by strange Status updates and Wall posts, many of them related to weight-loss plans, colon-cleansing products, and other website/product [...] |
|






Thursday, 1. October 2009 um 8:54 am
[...] This post was mentioned on Twitter by Rik Ferguson and Bharath Kumar. Bharath Kumar said: RT @rik_ferguson: Last night's blog: Facebook Colon Cleansing spam via Mobile Web – http://bit.ly/ox4Bp [...]