<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Social Threat &#124; Who said social meant secure? &#187; clickjacking</title>
	<atom:link href="http://socialthreat.com/tag/clickjacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://socialthreat.com</link>
	<description>Who said social meant secure?</description>
	<lastBuildDate>Sat, 18 Jun 2011 03:07:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Scam Spotting, No. 6: FarmVille Cash</title>
		<link>http://socialthreat.com/2010/03/23/scam-spotting-no-6-farmville-cash/</link>
		<comments>http://socialthreat.com/2010/03/23/scam-spotting-no-6-farmville-cash/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 11:00:44 +0000</pubDate>
		<dc:creator>Davezilla</dc:creator>
				<category><![CDATA[Scam Spotting]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[FarmVille]]></category>

		<guid isPermaLink="false">http://socialthreat.com/?p=410</guid>
		<description><![CDATA[
			
				
			
		
Farmville Cash scam
With over 88 million monthly users, it was inevitable that FarmVille would become a target for scams. Indeed, Social Threat&#8217;s Scott Vowels predicted this last week in a comment. The FamVille Cash scam is similar to the other album clickjacking scams we&#8217;ve been highlighting lately.
Here&#8217;s the attribute to watch out for:

Uses the correct 


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F23%2Fscam-spotting-no-6-farmville-cash%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F23%2Fscam-spotting-no-6-farmville-cash%2F&amp;style=normal&amp;service=bit.ly&amp;hashtags=clickjacking,Facebook,FarmVille" height="61" width="50" /><br />
			</a>
		</div>
<h2>Farmville Cash scam</h2>
<div id="attachment_412" class="wp-caption alignleft" style="width: 310px"><a href="http://socialthreat.com/wp-content/uploads/2010/03/scam-6-1.jpg"><img src="http://socialthreat.com/wp-content/uploads/2010/03/scam-6-1-300x216.jpg" alt="" title="Farmville Cash" width="300" height="216" class="size-medium wp-image-412" /></a><p class="wp-caption-text">Facebook scam: FarmVille Cash <br />Click image for full size version</p></div>With over 88 million monthly users, it was inevitable that FarmVille would become a target for scams. Indeed, Social Threat&#8217;s <a href="http://socialthreat.com/2010/03/18/scam-spotting-no-3-beware-of-tagged-facebook-gifts/#comments">Scott Vowels predicted this last week</a> in a comment. The FamVille Cash scam is similar to the other album clickjacking scams we&#8217;ve been highlighting lately.<br />
Here&#8217;s the attribute to watch out for:</p>
<ol>
<li>Uses the correct FarmVille logo for cash, but remember, FarmVille&#8217;s currencies are not called &#8220;FarmVille Cash,&#8221; they&#8217;re called &#8220;Farm Cash&#8221; and &#8220;Farm Coins.&#8221; You can see how easily people are being fooled by that.</li>
<li>&#8220;I&#8217;ve sent you a 900 farmville cash using farmville cash! Accept this gift and send one back!&#8221; Notice the poor grammar, the improper capitalization and the call to action which, if clicked, will install the scam application on your profile.</li>
<li>Friends are randomly tagged, as is the case in most of these scams, and the app is posted seemingly by itself.</li>
<li>Album poster is different than the photo poster, and the name seems to be three different ethnic groups in one.</li>
</ol>
<p>Additionally, we have two more screenshots for you. This first one shows that this app&#8217;s page has a number of anomalies itself.<br />
<div id="attachment_421" class="wp-caption alignright" style="width: 310px"><a href="http://socialthreat.com/wp-content/uploads/2010/03/scam-6-2.jpg"><img src="http://socialthreat.com/wp-content/uploads/2010/03/scam-6-2-300x235.jpg" alt="" title="Farmville Cash scam: app page" width="300" height="235" class="size-medium wp-image-421" /></a><p class="wp-caption-text">Click image for full size version</p></div>
<ol>
<li>No logo</li>
<li>1,454 people gave this app a 1-star rating.</li>
<li>108,000+ users, but only 2 friends</li>
<li>Category is &#8220;All&#8221; instead of &#8220;Games.&#8221;</li>
<li>No recent posts</li>
</ol>
<p>And finally, <a href="http://socialthreat.com/wp-content/uploads/2010/03/scam-6-3.jpg">look at the reviews</a> themselves. People who were scammed are speaking out against this app.</p>
<blockquote class="tip"><p>TIP: Just because you play a large, safe game like FarmVille, doesn&#8217;t mean that you&#8217;re safe from scams. By simply looking at the game page before adding it, you would easily see that this page is fishy. Over 100,000 people have fallen prey to this scam. Don&#8217;t be one of them. If FarmVille logos appear in your photo albums, delete them.</p></blockquote>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://socialthreat.com/2010/03/23/scam-spotting-no-6-farmville-cash/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Scam Spotting, No. 4: Fantasy Art</title>
		<link>http://socialthreat.com/2010/03/21/scam-spotting-no-4-fantasy-art/</link>
		<comments>http://socialthreat.com/2010/03/21/scam-spotting-no-4-fantasy-art/#comments</comments>
		<pubDate>Sun, 21 Mar 2010 21:22:46 +0000</pubDate>
		<dc:creator>Davezilla</dc:creator>
				<category><![CDATA[Scam Spotting]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[Facebook]]></category>

		<guid isPermaLink="false">http://socialthreat.com/?p=372</guid>
		<description><![CDATA[
			
				
			
		
&#8220;Several&#8221;
This is a very unusual version of the Facebook album scams hitting this week. While it has a lot of the standard characteristics of the others, it doesn&#8217;t pretend to be an app; it&#8217;s just a nice piece of artwork. It is also lacking the &#8220;Try it, really works!&#8221; comment. 
Here are the three characteristics 


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F21%2Fscam-spotting-no-4-fantasy-art%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F21%2Fscam-spotting-no-4-fantasy-art%2F&amp;style=normal&amp;service=bit.ly&amp;hashtags=clickjacking,Facebook" height="61" width="50" /><br />
			</a>
		</div>
<h2>&#8220;Several&#8221;</h2>
<p><div id="attachment_373" class="wp-caption alignleft" style="width: 310px"><a href="http://socialthreat.com/wp-content/uploads/2010/03/scam-4.jpg"><img src="http://socialthreat.com/wp-content/uploads/2010/03/scam-4-300x217.jpg" alt="" title="Scam Spotting, No. 4: Fantasy Art" width="300" height="217" class="size-medium wp-image-373" /></a><p class="wp-caption-text">Scam Spotting, No. 4: Fantasy Art<br />Click image for full size version</p></div>This is a very unusual version of the Facebook album scams hitting this week. While it has a lot of the standard characteristics of the others, it doesn&#8217;t pretend to be an app; it&#8217;s just a nice piece of artwork. It is also lacking the &#8220;Try it, really works!&#8221; comment. </p>
<p>Here are the three characteristics to watch out for:</p>
<ol>
<li>Fantasy artwork that has little or nothing to do with the member&#8217;s interests.</li>
<li>Multiple friends will be tagged in the photo. We&#8217;ve noticed that the Fantasy Art scam tags twice the number of friends as the other scams.</li>
<li>Album name is &#8220;several&#8221; and the &#8220;posted by&#8221; name will not be the owner of the Facebook profile.</li>
</ol>
<blockquote class="tip"><p><strong>TIP:</strong> If you see that you’ve been tagged in a photo, before clicking, see if it’s a friend of yours. If not, do not click. Ignore. If it is a friend, click through only to see the image. If it’s not a photo of you, leave the page or report it. It’s likely this scam, or one similar.</p></blockquote>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://socialthreat.com/2010/03/21/scam-spotting-no-4-fantasy-art/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scam Spotting No. 3: Beware of Tagged Facebook Gifts</title>
		<link>http://socialthreat.com/2010/03/18/scam-spotting-no-3-beware-of-tagged-facebook-gifts/</link>
		<comments>http://socialthreat.com/2010/03/18/scam-spotting-no-3-beware-of-tagged-facebook-gifts/#comments</comments>
		<pubDate>Thu, 18 Mar 2010 11:00:19 +0000</pubDate>
		<dc:creator>Davezilla</dc:creator>
				<category><![CDATA[Scam Spotting]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[Facebook]]></category>

		<guid isPermaLink="false">http://socialthreat.com/?p=347</guid>
		<description><![CDATA[
			
				
			
		
Life Gets Better…One Good Thought At A Time
This screenshot was sent in by  Stacy V., who spotted it on her friend&#8217;s Facebook account. She thought it was a little odd, checked with me and confirmed minutes later that it was definitely fraudulent.
At first this appears to be a legitimate gift from a friend except:

Gifts 


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F18%2Fscam-spotting-no-3-beware-of-tagged-facebook-gifts%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F18%2Fscam-spotting-no-3-beware-of-tagged-facebook-gifts%2F&amp;style=normal&amp;service=bit.ly&amp;hashtags=clickjacking,Facebook" height="61" width="50" /><br />
			</a>
		</div>
<h2>Life Gets Better…One Good Thought At A Time</h2>
<p><div id="attachment_348" class="wp-caption alignleft" style="width: 310px"><a href="http://socialthreat.com/wp-content/uploads/2010/03/scam-3.jpg"><img src="http://socialthreat.com/wp-content/uploads/2010/03/scam-3-300x107.jpg" alt="" title="scam 3" width="300" height="107" class="size-medium wp-image-348" /></a><p class="wp-caption-text">Facebook scam: Life Gets Better…One Good Thought At A Time<br />Click image for full-size version</p></div>This screenshot was sent in by  Stacy V., who spotted it on her friend&#8217;s Facebook account. She thought it was a little odd, checked with me and confirmed minutes later that it was definitely fraudulent.</p>
<p>At first this appears to be a legitimate gift from a friend except:</p>
<ol>
<li>Gifts do not appear in photo albums; only on walls or within the app itself.</li>
<li>The app URL is suspect (length).</li>
<li>GIfts are not generally tagged. You would generally receive a notice that you have received a gift via the Notifications listing.</li>
</ol>
<p>This scam looks like it does the same thing as &#8220;<a href="http://socialthreat.com/2010/03/16/scam-spotting-no-1/">Who is looking at my profile?&#8221;</a> that we profiled the other day. Unfortunately the screenshot she supplied me does not show the first comment (the others so far have the exact same first comment). I will update you as soon as I find that out.</p>
<blockquote class="tip"><p><strong>TIP:</strong> If you see that you’ve been tagged in a photo, before clicking, see if it’s a friend of yours. If not, do not click. Ignore. If it is a friend, click through only to see the image. If it’s not a photo of you, leave the page or report it. It’s likely this scam, or one similar.</p></blockquote>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://socialthreat.com/2010/03/18/scam-spotting-no-3-beware-of-tagged-facebook-gifts/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Scam Spotting, No. 2: The Sims? Not likely!</title>
		<link>http://socialthreat.com/2010/03/17/scam-spotting-no-2-the-sims-5626/</link>
		<comments>http://socialthreat.com/2010/03/17/scam-spotting-no-2-the-sims-5626/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 15:46:23 +0000</pubDate>
		<dc:creator>Davezilla</dc:creator>
				<category><![CDATA[Scam Spotting]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Sims]]></category>

		<guid isPermaLink="false">http://socialthreat.com/?p=338</guid>
		<description><![CDATA[
			
				
			
		
The Sims 5626
March 23 Update: Another variant of the Sims scam is appearing. The numbers will change from person to person, (i.e., Sims 9242, Sims 3876) but the app name is now appearing as &#8220;game-simulation&#8221; as in http://apps.facebook.com/game-simulation/ and oddly, the non-working link of http://apps.facebook.com//. This is likely a bad cut and paste.
The Sims scam 


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F17%2Fscam-spotting-no-2-the-sims-5626%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F17%2Fscam-spotting-no-2-the-sims-5626%2F&amp;style=normal&amp;service=bit.ly&amp;hashtags=clickjacking,Facebook,Sims" height="61" width="50" /><br />
			</a>
		</div>
<h2>The Sims 5626</h2>
<blockquote class="update"><p><strong>March 23 Update:</strong> Another variant of the Sims scam is appearing. The numbers will change from person to person, (i.e., Sims 9242, Sims 3876) but the app name is now appearing as &#8220;game-simulation&#8221; as in http://apps.facebook.com/game-simulation/ and oddly, the non-working link of http://apps.facebook.com//. This is likely a bad cut and paste.</p></blockquote>
<p><div id="attachment_339" class="wp-caption alignleft" style="width: 310px"><a href="http://socialthreat.com/wp-content/uploads/2010/03/scam-2.jpg"><img src="http://socialthreat.com/wp-content/uploads/2010/03/scam-2-300x213.jpg" alt="" title="The Sims 5626" width="300" height="213" class="size-medium wp-image-339" /></a><p class="wp-caption-text">Facebook scam: The Sims 5626<br />Click image for full size version</p></div>The Sims scam has made the rounds lately on Facebook. It works exactly like the <a href="http://socialthreat.com/2010/03/16/scam-spotting-no-1/">&#8220;Who is checking my profile?&#8221;</a> scam I wrote about yesterday. An album appears on the member&#8217;s Photos tab with numerous screenshots of the Sims, as if they were screens taken from the game. This is common on Facebook. A number of the Zynga games, including Farmville and Fishville have album creation capabilities.</p>
<p>Notice the anomalies however, that distinguish it from being an actual Sims game on Facebook.</p>
<ol>
<li>The title is always,&#8221;Let&#8217;s enjoy this game and be one of us.&#8221; The broken English should be a giveaway. EA Games would never allow that.</li>
<li>The &#8220;girls fighting in underwear&#8221; screenshot is common. There are four screens that I have come across in this scam, but this one is the most prevalent.</li>
<li>Sims 5626. In other words, not The Sims. Author is &#8220;Joe Caba&#8221;, not EA Games. Joe Caba, by the way, is not a member of Facebook. I checked.</li>
<li>Lastly, the ever present, &#8220;Try it, really works!!&#8221; comment rears its ugly head once again.</li>
</ol>
<blockquote class="tip"><p><strong>TIP:</strong> Always check first, if it was a <strong>friend</strong> who tagged you in a photo before adding any applications. Never assume because a screenshot of a game was used, that the app is from the actual game. It only takes 30 seconds to Google &#8220;The Sims&#8221; and find out that the Sims is made by EA, not Joe Caba.</p></blockquote>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://socialthreat.com/2010/03/17/scam-spotting-no-2-the-sims-5626/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scam Spotting: No. 1: Who is checking my profile</title>
		<link>http://socialthreat.com/2010/03/16/scam-spotting-no-1/</link>
		<comments>http://socialthreat.com/2010/03/16/scam-spotting-no-1/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 19:37:18 +0000</pubDate>
		<dc:creator>Davezilla</dc:creator>
				<category><![CDATA[Scam Spotting]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[Facebook]]></category>

		<guid isPermaLink="false">http://socialthreat.com/?p=323</guid>
		<description><![CDATA[
			
				
			
		
Who is checking my profile?
The first scam in this series is the &#8220;Who is checking my profile?&#8221; scam. It looks innocent enough. A graphic made up of friends&#8217; avatars and below it, their names tagged. 
Clicking to add the app yourself will screw you beyond belief. It will, like any Facebook app, ask for permission 


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F16%2Fscam-spotting-no-1%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F16%2Fscam-spotting-no-1%2F&amp;style=normal&amp;service=bit.ly&amp;hashtags=clickjacking,Facebook" height="61" width="50" /><br />
			</a>
		</div>
<h2>Who is checking my profile?</h2>
<p><div id="attachment_324" class="wp-caption alignleft" style="width: 310px"><a href="http://socialthreat.com/wp-content/uploads/2010/03/scam-1.jpg"><img src="http://socialthreat.com/wp-content/uploads/2010/03/scam-1-300x219.jpg" alt="" title="Who is checking my profile scam" width="300" height="219" class="size-medium wp-image-324" /></a><p class="wp-caption-text">Facebook Scam: Who is checking my profile?<br />Click image for full size version</p></div><br />
The first scam in this series is the <strong>&#8220;Who is checking my profile?&#8221;</strong> scam. It looks innocent enough. A graphic made up of friends&#8217; avatars and below it, their names tagged. </p>
<p>Clicking to add the app yourself will screw you beyond belief. It will, like any Facebook app, ask for permission to have access your data, but rather than safely use the data for normal usage like, &#8220;Hey it&#8217;s your birthday,&#8221; it proceeds to steal your personal info. Identity theft via social media. This is especially dangerous if you are using Facebook credits for games (like Farmville) as your bank or credit card info is now in the hands of the scammers.</p>
<p>Notice in the enlarged image the first comment: &#8220;Try it, really works!&#8221; This comment is consistent within this scam. The comment is then followed by a link to an app that seems like gibberish. A legitimate app would have a URL that mentions the app&#8217;s name.</p>
<blockquote class="tip"><p><strong>TIP:</strong> If you see that you&#8217;ve been tagged in a photo, before clicking, see if it&#8217;s a friend of yours. If not, do not click. Ignore. If it is a friend, click through only to see the image. If it&#8217;s not a photo of you, leave the page or report it. It&#8217;s likely this scam, or one similar.</p></blockquote>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://socialthreat.com/2010/03/16/scam-spotting-no-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

