In the past couple of days on Facebook, a couple of my friends have fallen for scams on Facebook – click here to see pictures of bin Laden! Similarly, a couple of other friends have fallen victim to the scam of finding out who’s tracking you (on Facebook) by clicking that link. The result is that a piece of malware reposts the image to all of your friends’ wall, effectively spamming your friends list.
Gary Warner over at the University of Alabama beat me to it, writing a post about this, saying the same thing – these are all scams:
The behavior of this particular scam is too cause a link to be posted BY YOU on all of your friends' walls. (There is another popular one going around -- "See Who Viewed Your Profile" -- that behaves in the same way. Facebook confirms that there is no app that can do that, and encourages us to use the "REPORT" feature when we see that. The danger starts if you click "Watch Video". DON'T DO IT!
Curse you, Gary Warner! I was going to write about this two days ago but I procrastinated! Anyhow, Warner has a list of recommendations from Facebook for its users:
These are all some pretty good hints. Here’s a couple of more that I tell my friends:
Those are my hints. Anyone have anything else?
To stop these scams cold, turn off javascript by default, and turn it on only for web sites you trust. This halts XSS scams like these in their tracks because they rely on running a script from another web site, not FaceBook, to perform the work. Turning off javascript by default and clicking the little paper at the right edge of the URL box in Chrome to turn it on for FaceBook means that no matter if you click a link, it won't run. More information and pics of the process for chrome can be found at jdnash.com/.../how-to-crush-facebook-spam-scams.
Hope this helps!
--Kubulai