Top Banner
Security threats on social networks Nithya Raman Senior Security Analyst Symantec
53

Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

May 08, 2019

Download

Documents

doannguyet
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Security threats on

social networks

Nithya Raman

Senior Security Analyst

Symantec

Page 2: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Facebook - 4th largest U.S. web property in

audience size with 157.2 million visitors

Linkedin.com -33.4 million visitors

Twitter.com -27.0 million visitors

All-time U.S.

audience highs

in May 2011

Data from comScore

Rise of social networking

Page 3: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

More than 750 million active users

50% of our active users log on to

Facebook in any given day

Average user has 130 friends

People spend over 700 billion minutes per

month on Facebook

People on Facebook install 20 million

applications every day Data from Facebook

Facebook Statistics

Page 4: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Attacks on social networks

Page 5: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Malicious applications

Page 6: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Both Facebook and Twitter allow third

party applications

Spam applications are a common

occurrence on these sites

Applications have also been used to

spread adware, phishing links and other

malware

Malicious applications on Facebook and Twitter

Page 7: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Automatically adds status messages and wall

posts/tweets

Usually leads to human verification

tests/surveys. You're tricked into believing that

you need to complete the survey in order to see

the promised content.

The scammers, meanwhile, are earning

commission for every survey completed, and are

using your Facebook account to spread the links

even further.

Spam applications

Page 8: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Facebook spam app

Page 9: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Facebook spam app

Page 10: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Spam Link Number of clicks

bit.ly/e9zZvk 281,167

bit.ly/dSUqN6 85,833

bit.ly/fCTbAB 71,372

bit.ly/fQEUl9 21,267

Clicks data for spam apps

Page 11: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Similar to spam applications, usually

spreads using wall posts/tweets and

messages

Applications can redirect to

- fake codec/antivirus pages

- phishing pages

- other malware/exploits

Malware applications

Page 12: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Adware App

Page 13: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Adware App

Page 14: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Twitter spam app

» Screenshots from Sophos

Page 15: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Koobface

Page 16: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

First appeared in late 2008

Spreads across social networks like

Facebook, MySpace and Twitter

Uses wall posts/tweets containing a link

that usually leads to a page which looks

like a YouTube video

Offers a fake Adobe Flash Player update –

Koobface Zombie executable

What is Koobface?

Page 17: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends
Page 18: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Spread through social networks

Steal confidential information, software license keys

Redirect web browsing to malicious sites and inject

advertising

Intercept Internet traffic and block access to certain

Internet sites

Download additional files/pay-per-install software

Break CAPTCHAs, determine if a link is blocked by

Facebook

Create new Blogspot accounts and pages

Modify the Hosts file

Koobface behaviour

Page 19: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Wall Posts/Tweets

Direct messages

Koobface links are usually accompanied

with enticing messages such as

Cool Video <malicious link>

LOL <malicious link>

Last Video <malicious link>

Spreading techniques

Page 20: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Redirection from blogspot.com pages

De-obfuscated code:

Page 21: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Fake Youtube Video

Page 22: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Malicious link Count

Blogspot.com pages 15841

'bit.ly' shortened

links

37133

Google links

184

Other links 1035

Koobface data

Blogspot.com pages

15841 29.2%

bit.ly' short links 37133 68.5%

Google links 184

0.3%

Other links 1035 1.9%

Koobface links

Total number of unique Koobface links :54193

Page 23: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Total number of clicks 3,671,541

Average number of clicks per link 99

Maximum number of clicks per link 12836

Number of links with over 10K clicks 73

‘bit.ly’ link statistics

Page 24: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Multiple redirections

Shortened links

69% of links collected were „bit.ly‟ short links

Referrer URL check

Google news page/ other clean pages in case Referrer

is not set

User Agent check

Broken URLs

Adding random text just before the valid URL link

Detection evasion techniques

Page 25: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Script Attacks

Page 26: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Manual script attacks

Clickjacking

Cross-Site Scripting (XSS)

Types of script based attacks

Page 27: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Manual script scams

Page 28: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

User is lured with a message as bait to a

prepared site.

User is asked to copy a Javascript to the

browser address bar and to click the

„Enter‟ key.

Manual script scams

Page 29: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Updates your FB status with these spam messages and

also post on your friends wall.

Sends chat messages to friends

Adds “Likes” to different Facebook pages

Tags you in images

Create an event and send an invitation to all your

friends.

Facebook provides a personalized email id, using which

you can update your FB status. This script tries to gain

access to this personalized email id, so the hacker can

update your FB status anytime.

http://www.facebook.com/mobile/?v=photos

Script behavior

Page 30: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Sample scripts

Page 31: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Manual script scam – Wall posts

Page 32: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Osama scam

Page 33: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Profile Views

Page 34: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Clickjacking

Page 35: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

The practice of deceptively directing a

website visitor‟s clicks to an undesired

element of another site

Attacker overlays multiple transparent or

opaque layers to trick a user into clicking

on a button or link on another page

Clicks meant for original page are hijacked

and routed to another page

What is clickjacking?

Page 36: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Facebook like-jacking

Page 37: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Facebook like-jacking

Page 38: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Facebook like-jacking

Page 39: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Cross-Site Scripting

(XSS) attacks

Page 40: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Cross-Site Scripting attacks are a type of

injection problem, in which malicious

scripts are injected into the otherwise

benign and trusted web sites.

Facebook has been vulnerable to both

persistent and non-persistent XSS attacks

Cross-site scripting on Facebook

Page 41: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Vulnerability existed in the mobile API

version of Facebook due to insufficient

JavaScript filtering

hxxp://m.facebook.com/connect/prompt_fee

d.php?display=wap&user_message_prom

pt=<script>alert(document.cookie);</sc

ript>

Non-persistent XSS – Facebook worm (March 2011)

Page 42: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

The shortened tinyurl.com link redirects to the following URL(de-

obfuscated)

hxxp://m.facebook.com/connect/prompt_feed.php?display=wap&user_

message_prompt='<script>window.onload=function(){document.for

ms[0].message.value='jangan salahin w kalo lo bakal ngakak

ngeliat ni orang :D

http://tinyurl.com/sampahh';document.forms[0].submit();}</script>

This URL automatically adds a wall post with the message 'jangan

salahin w kalo lo bakal ngakak ngeliat ni orang :D

hxxp://tinyurl.com/sampahh'.

Non-persistent XSS – Facebook worm

Page 43: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Twitter trends attacks

Page 44: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Look for latest news and events – Twitter

trending topics

http://api.twitter.com/1/trends/current.json

Twitter trending topics poisoning

Page 45: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Mask the malicious URLs

URL-shortening services are commonly

used on services like Twitter in order to

conserve space

Various shortening services such as

tinyurl.com, bit.ly, tiny.cc have been used

to mask URLs

Twitter trending topics poisoning

Page 46: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Compose a collection of messages to

tweet

Create messages with Twitter trending

topics/ hashtags planted randomly into the

message

Start tweeting!

Tweets are sent from a different

fraudulent/ compromised accounts

Twitter trending topics poisoning

Page 47: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Phishing

Page 48: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Spoofed websites designed to fool

recipients into divulging their credentials

Again, these scams are usually

accompanied with enticing messages

Wall posts, messages or tweets could

contain

- direct links to the phishing site

- obfuscated shortened links

- via. applications

Facebook and Twitter phishing scams

Page 49: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Facebook Phishing wall posts

Page 50: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Facebook Phishing page

Page 51: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Link on the tweet First Redirection Second redirection

http://t.co/QYQfGIa http://kurz.es/8b3fcb http://itwittiler.com/twitterlogin1

http://kurz.es/8b3fcb

http://itwittiler.com/twitterlog

in1

http://t.co/lAyDmRZ http://i2h.de/b0tb

http://xxx-black-

book.com/twitterlogin1/

http://t.co/9hk72A5 http://kurz.es/8b3fcb http://itwittiler.com/twitterlogin1

http://t.co/PaFDmUJ http://kurz.es/8b3fcb http://itwittiler.com/twitterlogin1

http://i2h.de/b0tb

http://xxx-black-

book.com/twitterlogin1/

Twitter phishing links

Page 52: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Twitter phishing page

Page 53: Security threats on social networks - securitybyte.org · More than 750 million active users 50% of our active users log on to Facebook in any given day Average user has 130 friends

Questions?

[email protected]

Thank You!