Saturday, August 27, 2011

mileyrespect info

mileyrespect info, www.mileyrespect.info. It’s been a while since I updated this blog. I’ve been busy in the past year so for now, I’m still finding a time to make one.



I want to share with you about the likejacking attack on Facebook. Basically, the likejacking is not new. It was publicly disclosed a long time ago maybe a year or so. I noticed that most likejacking attacks are not blocked by Security companies.



First what is likejacking?



Likejacking is a malicious technique of tricking users of a website into posting a Facebook status update for a site they did not intentionally mean to "like."



The term "likejacking" came from a comment posted by Corey Ballou in the article How to "Like" Anything on the Web (Safely), which is one of the first documented postings explaining the possibility of malicious activity regarding Facebook's "like" button.



And here is the example that I found today……….



Clicking the link will open a new browser and go to the site miley-respect.info. When I analyzed the site, it contains code that several redirections takes place as below:



http://miley-respect.info -redirects_to- http://www.omg-girl.info/ -redirects_to- http://www.omg-girl.info/ -redirects_to- http://jerrynoob.info/np



Well if we think deeply there are several possible reasons why they are doing this kind of redirection chain.



1. Easy to change the end point of the attack.



2. Not easy to track if you only got the end point or before the end point domain.



3. And there’s much more… haha.



Then after the redirections and as of this writing, it will end up to the site http://jerrynoob.info/np

No comments:

Post a Comment