Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Clickjacking Vulnerability Spamming the Userโ€™s Facebook Wall

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Clickjacking Vulnerability Spamming the Userโ€™s Facebook Wall


๐Ÿ’ก Newskategorie: Sicherheitslรผcken
๐Ÿ”— Quelle: ehackingnews.com


A Polish Security Researcher who works under the name of Lasq, found a malevolent spam campaign that spams the users' Facebook wall by exploiting the vulnerability. The said vulnerability came into his notice after he saw it repeatedly being abused by a Facebook spammer group.


The vulnerability as indicated by Lasq is known to reside in the mobile version of the Facebook for the most part through popups while the desktop version stays unaffected.


The link that is the root of all the spamming gives off an impression of being facilitated in an Amazon Web Services (AWS) bucket and diverts the user to a comic website, after they are requested to confirm their ages in French. In any case, even after the user has tapped on the link and done whatever it requested, it was still found to show up on the user's Facebook wall.


At the point when Lasq researched about this issue he found that the spammers were utilizing codes to abuse the IFrame component of Facebook's mobile sharing dialog. He tested for it then with the popular browsers, like the Chrome, Chromium, Edge, IE, Firefox and every other program which displayed X-Edge-Options error and thusly published a blog post with the technical subtleties. He suspected clickjacking.


Later he gathered that because Facebook had disregarded the X-Edge-Options header for the mobile sharing discourse, the "age verification" popup which displayed prior, skirted Facebook's system.



Lasq reached out to Facebook, yet shockingly they declined to fix the issue contending that it is operating in as intended and the case has been closed within 12 hours from an underlying report and clickjacking is an issue just when an attacker some way or another alters the state of the users' account.


On being reached by ZDNet, Facebook essentially stressed on the part that they are consistently enhancing their "clickjacking detection systems" to forestall spam.


...



๐Ÿ“Œ Clickjacking Vulnerability Spamming the Userโ€™s Facebook Wall


๐Ÿ“ˆ 62.2 Punkte

๐Ÿ“Œ Clickjacking Bug in Facebook Being Abused By Attackers To Post Spam On Your Facebook Wall


๐Ÿ“ˆ 36.19 Punkte

๐Ÿ“Œ The โ€œInternet of Stranger Thingsโ€ Wall, Part 2 โ€“ Wall Construction and Music


๐Ÿ“ˆ 26.61 Punkte

๐Ÿ“Œ The โ€œInternet of Stranger Thingsโ€ Wall, Part 2 โ€“ Wall Construction and Music


๐Ÿ“ˆ 26.61 Punkte

๐Ÿ“Œ Vision Pro wall-to-wall: Pros, cons, grins and gripes! [The CultCast]


๐Ÿ“ˆ 26.61 Punkte

๐Ÿ“Œ Facebook Is Spamming Users Via Their 2FA Phone Numbers


๐Ÿ“ˆ 25.32 Punkte

๐Ÿ“Œ Facebook accused of spamming 2FA phone numbers


๐Ÿ“ˆ 25.32 Punkte

๐Ÿ“Œ Facebook Removes Hundreds of Accounts Spamming Political Info


๐Ÿ“ˆ 25.32 Punkte

๐Ÿ“Œ Brands Are Spamming WhatsApp Users in India, Facebook's Largest Market


๐Ÿ“ˆ 25.32 Punkte

๐Ÿ“Œ Spamming Someone from PayPal


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Spamming Someone from PayPal


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ UK credit broker fined ยฃ120k for spamming folk with five million texts


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Microsoft Is Spamming Windows 10 File Explorer With Ads For OneDrive Storage


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Botnet Tweeting, Spamming Porn Shut Down


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Moneysupermarket fined ยฃ80,000 for spamming seven million customers


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ 43 Million Email Addresses Leaked By Email Spamming Service


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ TalkTalk kept my email account active for 8 years after I left โ€“ now it's spamming my mates


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Tortuga: A SMS Spamming tool written in Python 2


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Tortuga: A SMS Spamming tool written in Python 2


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Emails for Spamming 21/06/2019 - HOT/US/NZ


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Apple Starts Spamming iPhone, iPad Users with iOS 11 Teasers


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Microsoft Spamming Windows 10 Users with โ€œLink Your Phone and PCโ€ Notifications


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Preview spamming email's pdf file in hotmail


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Rainbow Six Siege โ€˜crouch spammingโ€™ fix on the way


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Someone Is Spamming and Breaking a Core Component of PGP's Ecosystem


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Phorpiex botnet made $115,000 in five months just from mass-spamming sextortion emails


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ GoFile Spammer - Inbox spamming tool valid for the next 3 hours.


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Someone Is Spamming and Breaking a Core Component of PGPโ€™s Ecosystem


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Spamming&Hacking Tools


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Any suspisous activities (hacking/spamming) in the last few days?


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Spamming needs to stop ?


๐Ÿ“ˆ 21.14 Punkte

๐Ÿ“Œ Money to be made from spamming


๐Ÿ“ˆ 21.14 Punkte











matomo