E-victims.org: Facebook video threats

Tony

What Consumer Founder
Apr 7, 2008
18,307
3
38
Bolton
If someone sends you an email or wall posting about a Facebook video but before you can view it you first have to upgrade the flash player - you've landed a malicious site don't click on anything. Hit alt ctrl delete to get to the Windows' task manager, go to applications and end your browser.

F-Secure blog writes about a fake Facebook site with a malicious JavaScript that uses the old "Flash Player upgrade installation" trick — but with a slight twist.

As usual, the viewer thinks they're going to see a video, if they just upgrade their Player:


But first they have to download and install the "upgrade":



The unusual thing is, this "upgrade" comes with a CAPTCHA pop-up:



The request is displayed at random times and doesn't actually do anything. Anything entered into the field by the user results in this being displayed:



The screen will close after a few tries, but will still continue to appear off and on.

While the user is having dubious fun with the CAPTCHA test, the...

Facebook video threats