1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Facebook Scam Abuses Linkedin Redirector

Discussion in 'Security Updates' started by starbuck, Jul 4, 2011.

  1. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Security researchers have identified a new Facebook scam which abuses LinkedIn's open URL redirector in order to bypass spam filters and lend credibility to the fake messages.

    Users are lured with rogue wall posts that read: "The Video Tweet That Just Ended Justin Biebers Career For Good" and appear to link to pages hosted on linkedin.com.

    In reality, the links lead to http://linkedin.com/redirect?=[scam_URL], a redirect script that further directs users to the scam page.

    The landing page displays a censored video thumbnail of someone who resembles Justin Bieber and a girl who hides her face. The image is enticing enough for users to want to press the play button.

    However, doing so will not allow them to see any recording. Instead, they will be asked to fill in a survey before they are allowed to access the content. Scammers earn commission money through affiliate marketing schemes for every user who fills in one of the surveys.

    Using open redirectors hosted on high-profile domains is not a new technique. Up until recently, spammers used to abuse Facebook's own redirect script, however, the company signed a partnership with Web of Trust (WOT) to check all outgoing links.

    The new URL filtering system seems to be working with scammers finding it increasingly hard to keep their campaigns online for long. WOT is backed up by a large community of users who can react quickly to flag malicious links.

    Meanwhile, LinkedIn's redirector doesn't seem to enforce the same restrictions or checks and thanks to the high-profile nature of the domain can easily pass Facebook's URL filtering mechanism.

    The new technique is proof of the inventiveness of scammers who are continuously adapting to the anti-abuse measures enforced by Facebook and is a clear sign that users also need to employ third-party Web protection solutions.


    Source:
    http:/ ews.softpedia.com ews/Facebook-Scam-Abuses-LinkedIn-Redirector-209613.shtml
     

Share This Page