No need to worry if you become one of the victims McD video which spread through the invitation on Facebook recently.According Vaksincom, one internet security solution provider in Indonesia, attack or exploitation is not to steal your password.However, you should be wary because the maker of the application may be misusing your account to spread all kinds of information.
“Most likely makers ‘virus’ or this application does not commit identity theft or not to commit identity theft with this exploitation, but this application was allowed by Facebook to send messages automatically to all contacts on Facebook,” said Tan Aa, from Vaksincom , in his e-mail on Saturday (30/10/2010).
This does not mean necessarily a secret password known to the makers of this virus. So this case is different with the case of phishing (fraudulent) site up that is aiming to steal credentials (username and password up). However, this malware authors designed it in such a way that it came as if it were an invitation event in viral spread to many people. The goal is not clear whether simply to speak ill of McD or collect the victim to be used at any time.
Weaknesses people
Before this case came on up, and was previously circulated a similar mode. At that time, the supply is the link to watch a video clip titled “Candid Camera Prank.” If it had circulated through status, this time circulating through the invitation (Event Invitation). If the first, when the link is clicked, the malicious program to get started installing applications in your account up automatically without the need to consent even if the account owner, and after that to post the same message with a link to all contacts from the account up the victim.
This mode makes up changing the rules a third-party application installation. To be more difficult to infiltrate malicious programs, third party applications have to ask permission to users up to do the installation. They still can access information about anything, but must be consent of the user up.
Technically was inhibited, apparently evil perpetrators advantage of Facebook users who are difficult to overcome only through the security settings when deploying video link McD. Actually security is done by up was good enough, in which each installation of the application on your Facebook account must receive prior approval from the owner of the account by clicking “Allow”. However, as always, computer users generally have a positive life principles once so that if given the choice to click “Allow” or “Not Allow”, many will click on “Allow” without seeing again what can be accessed application. That’s what causes this exploitation can successfully transmit itself.
Keep a record and concern for computer users, this exploitation occurs in the API up and not on the operational system (OS) your computer. That is, no matter what OS you use (Windows, Linux, Mac or Free BSD), to the extent you use the account up and approve (“Allow”), a Facebook account you will be infected by this exploitation and send event invitations to all your contacts .
If you click the link provided and you will be delivered on site confirmation Public Event. Actually if you just click on “I’m Attending”, “Maybe”, or “No”, your account will not be exploited because no application is installed. However, if you click the “Tiny URL” is given, you will get a confirmation screen that you must be logged in to use HD Video Account.
If the victim “drool” over the two banners that appears that says “Shocking McTruth”, “You’ll Never Believe This!” and clicking the [Login] new installation confirmation screen will display the application. Once you click [Allow] then the application (malware) will be active on your account and send the Event Invitation to all your contacts.
One key to successful exploitation of this malware is because the author uses interesting video to lure. Do not be attracted to click because it is the result of testing potatoes compared with McDonald’s burgers and fries the other, where the final conclusion of the video is all the food except the potato McDonald’s damaged and moldy after settling for several days or weeks. Potato penjamuran McDonald’s did not experience at all and thought to contain material that is harmful to humans. In addition, the links provided are also using the video with the title “Super Size Me” which discusses the problem of obesity in America are caused by an increased consumption of fast food.
Videos are used were deliberately uploaded on YouTube on October 22, 2010 by a user named MrGamesFree, while the original video is actually taken from www.ebaumsworld.com uploaded in June 2007.