• On TV.com: Big Brother 11 cast
August 25, 2008 5:33 AM PDT

Facebook appears to be controlling 'wall spam'

by Caroline McCarthy

On Sunday, I had an e-mail alert about someone writing on my Facebook wall--a college acquaintance with whom I hadn't spoken in quite some time. As it turns out, I was a victim of "wall spam," a recent phenomenon on Facebook in which automated spam posts show up on members' message walls. It's similar to a wave of profile spam that swept News Corp.'s MySpace a few years ago.

The message in question read, "Some thinks you are special and has a hot^crush on you. Find out who it could be!! ;)" with a link to a Flash file claiming to be hosted on the imageshack.us domain.

But by the time I navigated to my Facebook profile to get rid of the spammy (and possibly virus-ridden) message--within an hour or two of the notification showing up in the first place--the wall post was gone. This means one of either two things: someone else saw the message on my profile and flagged it, or Facebook is actively policing the site to keep it under control, probably by searching for duplicates of a known spam message.

Of course, an hour or two is still a big enough frame of time for people to click on the link and get their computers loaded with some nasty new malware.

I've asked Facebook for comment on exactly what their strategy is and whether any members' login credentials are getting compromised by this spam or virus. I'll update when I hear back.

"Wall spam" rose to notoriety earlier this month, when members started noticing the phenomenon, and security firms started flagging worms that were spreading via Facebook members' walls and installing malware when a link in the message was clicked. The company has recommended antivirus fixes and says it's acting fast.

The Silicon Alley Insider reported earlier this month that Facebook had been deactivating links in identified spam posts; removing the posts entirely is a more aggressive measure.

"If we get a report of a bug or a hole from a user, a security researcher, a reporter, blogger, or anyone, we check it out and fix it as quickly as possible," Facebook security chair Max Kelly wrote several weeks ago on the company blog in response to another virus. "In fact, we appreciate it when help comes our way from the many security experts and organizations out there."

Originally posted at The Social
Caroline McCarthy, a CNET News staff writer, is a downtown Manhattanite happily addicted to social-media tools and restaurant blogs. Her pre-CNET resume includes interning at an IT security firm and brewing cappuccinos. E-mail Caroline.
Recent posts from Webware
URL shortening is hot--but look before you leap
Marc Andreessen launches new venture fund
4chan may be behind attack on Twitter
Firefox 3.5 and the potential of Web typography
Sites that help you lodge complaints
Google App Engine misfires
Microsoft: Bing needs to improve when news breaks
Google finally sued by makers of Finally Fast
Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
by cuwickliffe August 25, 2008 10:57 AM PDT
I also some some weird stuff this weekend, but rather than through wall spam, I got messages in my inbox that purportedly went to a site that kind of looked like YouTube, but obviously wasn't and used an onLoad parameter to try to download an .exe file. These were "from" people I never talk to, but are on my friends list.
Reply to this comment
by jason21193 August 25, 2008 3:27 PM PDT
I also along with a few of my friends received an e-mail over the weekend that said RE: Hi My Friend. "Is This You Having Sex" and a bunch of letters and numbers which appeared to be a link to a video but it wasn't one of my friends made the mistake of opening it and it sent everyone he knew on his friends list and sent them the same message from his profile what the worm actually does I do not know but be advised DO NOT OPEN ANY OF THESE MESSAGES. Facebook manage to catch a couple of these but it went out in such a large quantity some slipped through the cracks so be careful
Reply to this comment
by Harrison912 August 25, 2008 6:58 PM PDT
I use FaceBook primarily to raise awareness for my safety and security web site and products so I am always concerned about safety since it's my business. I appreciate everything FaceBook is doing to keep the community there safe.
Reply to this comment
by Tinman52 August 25, 2008 7:09 PM PDT
So, did you click on a bad email or is you're profile not restricted to just friends? Either way, unless I'm misreading the article, if you're getting random wall messages, it sounds like user error.
Reply to this comment
by mhcb13 August 26, 2008 3:34 AM PDT
haha... www.fanebook.com
watch out for it
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next
advertisement

About Webware

Say No to boxed software! The future of applications is online delivery and access. Software is passé. Webware is the new way to get things done.

Add this feed to your online news reader

Webware topics

Look before leaping to short URLs

Fueled by Twitter's rise, services that scrunch Web addresses are taking off. They bring a host of problems, but some are working to fix them.

In Utah desert, it's bombs away

road trip At the massive Utah Test & Training Range, the Air Force runs 15,000 sorties a year to ensure that pilots and weapons are on the mark.
• Photos: Training and testing

advertisement

Inside CNET News

Scroll Left Scroll Right