<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; facebook password</title>
	<atom:link href="http://www.darknet.org.uk/tag/facebook-password/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Fri, 30 Jul 2010 10:38:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Facebook E-mail Spam Conceals Malware Attack</title>
		<link>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/</link>
		<comments>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 09:47:07 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[anti sandbox]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[bredolab]]></category>
		<category><![CDATA[bredolab trojan]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[drone]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebook password]]></category>
		<category><![CDATA[facebook security]]></category>
		<category><![CDATA[facebook spam]]></category>
		<category><![CDATA[hacking-facebook]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[password theft]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[sandbox]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[zombie]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2236</guid>
		<description><![CDATA[Facebook has had a fair share of problems, being a large community of course it&#8217;s going to be a ripe target for spammers, scammers and malware distributors. The latest to hit is a spam e-mail claiming to be from the Facebook team that actually spreads a nasty piece of malware called Bredolab. It&#8217;s also been [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-BodyRec */
google_ad_slot = "8649785837";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p><a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> has had a fair share of problems, being a large community of course it&#8217;s going to be a ripe target for spammers, scammers and malware distributors.</p>
<p>The latest to hit is a spam e-mail claiming to be from the Facebook team that actually spreads a nasty piece of malware called Bredolab. It&#8217;s also been observed the trojan will connect to additional servers to install more malware.</p>
<p>The ultimate goal as usual is to make the victims part of a <a href="http://www.darknet.org.uk/tag/botnet/">botnet</a>. </p>
<blockquote><p>Researchers at several security firms have uncovered a spam campaign targeting Facebook users. The e-mails, which pose as communications from Facebook about password resets, contain a nasty downloader that ultimately makes users part of a notorious botnet.</p>
<p>Researchers at several security firms have tied the Bredolab Trojan to a spam campaign targeting Facebook users.</p>
<p>The malware is being blasted out by spammers in e-mails claiming to come from “The Facebook Team.&#8221; Inside the e-mails is a message that the recipient&#8217;s Facebook password has been changed. In order to get the new one, recipients are told to open the accompanying attachment containing the malware.</p>
<p> Researchers at Websense told eWEEK Oct. 27 that they have observed more than 350,000 of the messages. On the company’s blog, researchers explained that the malware connects to two servers to download additional malicious files. Among them is Pushdo, also known as Cutwail.</p></blockquote>
<p>This spam campaign seems to be generating some fairly high levels of traffic meaning whoever is behind it is pretty serious and committed to this vector for disseminating malware.</p>
<p>Social engineering isn&#8217;t a new method for propagating malware as always the weakest link is never the technological barriers but is always the stupidity/greed/gullibility of humans.</p>
<p>You can ALWAYS hack the wetware.</p>
<blockquote><p>&#8220;One of the first things we saw this Trojan horse download was the Pushdo bot which began spamming out more of these Facebook password reset emails,” according to M86 Security. </p>
<p>MX Logic noted that Bredolab bypasses firewalls by injecting its own code into the legitimate process svchost.exe and explorer.exe. It also contains anti-sandbox code to thwart researchers, and creates the following files: %AppData%\wiaservg.log, %Windir%\temp\wpv861256600826.exe and %Programs%\Startup\isqsys32.exe. Bredolab also creates the processes isqsys32.exe and svchost.exe.</p>
<p>Sophos is detecting the malware as Troj/BredoZp-M or Mal/Bredo-A.</p>
<p>&#8220;Don&#8217;t make life easy for the hackers hell-bent on infecting your computer, stealing your identity and emptying your bank account &#8211; exercise caution when you receive unsolicited emails and protect your computer with up-to-date security software,&#8221; Graham Cluley, senior technology consultant at Sophos, advised in a blog post.</p></blockquote>
<p>It looks like a pretty advanced piece of malware code which evades firewall measures and even tries to thwart analysis by AV companies.</p>
<p>Anti sandbox code and process injection, these bad guys are getting smart.</p>
<p>That does not bode well for the average citizen.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Facebook-Password-Spam-Conceals-Malware-Attack-635899/?kc=rss">eWeek</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Facebook+E-mail+Spam+Conceals+Malware+Attack+http://bit.ly/XheUR+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;t=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FBController &#8211; The Ultimate Utility to Control Facebook Accounts</title>
		<link>http://www.darknet.org.uk/2009/05/fbcontroller-the-ultimate-utility-to-control-facebook-accounts/</link>
		<comments>http://www.darknet.org.uk/2009/05/fbcontroller-the-ultimate-utility-to-control-facebook-accounts/#comments</comments>
		<pubDate>Thu, 07 May 2009 10:26:46 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[control facebook]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebook controller]]></category>
		<category><![CDATA[facebook password]]></category>
		<category><![CDATA[facebook security]]></category>
		<category><![CDATA[fbcontroller]]></category>
		<category><![CDATA[hack facebook]]></category>
		<category><![CDATA[hacking-facebook]]></category>
		<category><![CDATA[hijack facebook]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1753</guid>
		<description><![CDATA[Just to put a downer on all the script kiddies, this utility WILL NOT hack/crack Facebook passwords or accounts. You need to feed it biscuits (cookies) before you can do anything. You can get the target&#8217;s cookie by sniffing, XSS, social engineering, ARP Poison-Sniffing, Scroogle search or however you like. Once you have the cookies [...]]]></description>
			<content:encoded><![CDATA[<p><!--adsense--></p>
<p>Just to put a downer on all the script kiddies, this utility WILL NOT hack/crack Facebook passwords or accounts.</p>
<p>You need to feed it biscuits (cookies) before you can do anything.</p>
<p>You can get the target&#8217;s cookie by sniffing, XSS, social engineering, ARP Poison-Sniffing, <a href="http://www.scroogle.org/">Scroogle</a> search or however you like.</p>
<p>Once you have the cookies you can use FBController to have Full control over the target&#8217;s Facebook account.</p>
<p>Login to your Facebook account and sniff your own cookie OR collect a few live Facebook Biscuit/s of your Target/s.</p>
<p>Till now FBController version 1.0 uses your Target&#8217;s provided cookie and only :</p>
<p>A > Downloads the HomePage.<br />
B > Allows you to Update the Target&#8217;s Wall and<br />
C > Retrieve your Target&#8217;s Friend&#8217;s List</p>
<p>There are many APIs available to write apps and 3rd party Tools for FB in Java, Perl, .NET, etc.</p>
<p>FBConTroller was entirely written without knowing any of Facebook&#8217;s Dev API&#8217;s. Considering the above along with Facebook&#8217;s complexity, the next version might take some time to get released</p>
<p>You can download FBController here:</p>
<p><a href="http://www.fileden.com/files/2008/9/18/2104312/FBConTroller.RAR">FBConTroller.RAR</a></p>
<p><!--adsense#New468--></p>
<p>Or read more <a href="http://my.opera.com/quakerdoomer/blog/fbcontroller-facebook-controller-the-ultimate-facebook-controller-without-the-pa">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=FBController+%E2%80%93+The+Ultimate+Utility+to+Control+Facebook+Accounts+http://bit.ly/5WUwx+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/05/fbcontroller-the-ultimate-utility-to-control-facebook-accounts/&amp;title=FBController+%E2%80%93+The+Ultimate+Utility+to+Control+Facebook+Accounts" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/05/fbcontroller-the-ultimate-utility-to-control-facebook-accounts/&amp;title=FBController+%E2%80%93+The+Ultimate+Utility+to+Control+Facebook+Accounts" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/05/fbcontroller-the-ultimate-utility-to-control-facebook-accounts/&amp;t=FBController+%E2%80%93+The+Ultimate+Utility+to+Control+Facebook+Accounts" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/05/fbcontroller-the-ultimate-utility-to-control-facebook-accounts/&amp;title=FBController+%E2%80%93+The+Ultimate+Utility+to+Control+Facebook+Accounts" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/05/fbcontroller-the-ultimate-utility-to-control-facebook-accounts/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
