<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Guy&#039;s super-duper site</title>
	<atom:link href="http://gfreeman.wordpress.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://gfreeman.wordpress.com</link>
	<description>Yet another Freeman spectacular</description>
	<lastBuildDate>Sat, 17 Oct 2009 16:05:22 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on How many countries can a citizen visit without a visa? [Bonus Economist Graph Edition] by JOHNSON,NIGERIAN</title>
		<link>http://gfreeman.wordpress.com/2009/03/05/how-many-countries-can-a-citizen-visit-without-a-visa-bonus-economist-graph-edition/#comment-3600</link>
		<dc:creator>JOHNSON,NIGERIAN</dc:creator>
		<pubDate>Sat, 17 Oct 2009 16:05:22 +0000</pubDate>
		<guid isPermaLink="false">http://gfreeman.wordpress.com/?p=104#comment-3600</guid>
		<description>WHICH IS VISA FREE TO GUINEA REPUBLIC</description>
		<content:encoded><![CDATA[<p>WHICH IS VISA FREE TO GUINEA REPUBLIC</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Ainu of Japan believe that the world is supported by a Giant Trout and that sin is caused by otters. by Anonymous</title>
		<link>http://gfreeman.wordpress.com/2009/05/25/the-ainu-of-japan-believe-that-the-world-is-supported-by-a-giant-trout-and-that-sin-is-caused-by-otters/#comment-3598</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sun, 20 Sep 2009 20:43:08 +0000</pubDate>
		<guid isPermaLink="false">http://gfreeman.wordpress.com/?p=138#comment-3598</guid>
		<description>its not very good you know!!!</description>
		<content:encoded><![CDATA[<p>its not very good you know!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook trojan? by Mark</title>
		<link>http://gfreeman.wordpress.com/2009/09/03/facebook-trojan/#comment-3593</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Sun, 06 Sep 2009 16:52:39 +0000</pubDate>
		<guid isPermaLink="false">http://gfreeman.wordpress.com/?p=177#comment-3593</guid>
		<description>Thanks for sharing! I received a notification this morning, and your site was the first one I checked out! : ) - Captured a screen cap and posted it to photobucket and on FB to share with friends. I&#039;ve also sent it along to FB support.



Thanks again!
-Mark</description>
		<content:encoded><![CDATA[<p>Thanks for sharing! I received a notification this morning, and your site was the first one I checked out! : ) &#8211; Captured a screen cap and posted it to photobucket and on FB to share with friends. I&#8217;ve also sent it along to FB support.</p>
<p>Thanks again!<br />
-Mark</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook trojan? by Sam</title>
		<link>http://gfreeman.wordpress.com/2009/09/03/facebook-trojan/#comment-3592</link>
		<dc:creator>Sam</dc:creator>
		<pubDate>Sat, 05 Sep 2009 17:06:41 +0000</pubDate>
		<guid isPermaLink="false">http://gfreeman.wordpress.com/?p=177#comment-3592</guid>
		<description>I received a notification that I had a gift from a friend. Clicked it, it showed the same website url, but nothing happened. I am using Windows 7 with google chrome.

I have mcafee anti-virus on my computer as well. I tried doing an update and it said that my gdeltaavv.ini file was corrupt and could not update the DAT. I ran it again and it downloaded fine. Coincidence? I have no idea.

I changed my facebook password on another machine and i&#039;m running a full system scan. Any other suggestions?</description>
		<content:encoded><![CDATA[<p>I received a notification that I had a gift from a friend. Clicked it, it showed the same website url, but nothing happened. I am using Windows 7 with google chrome.</p>
<p>I have mcafee anti-virus on my computer as well. I tried doing an update and it said that my gdeltaavv.ini file was corrupt and could not update the DAT. I ran it again and it downloaded fine. Coincidence? I have no idea.</p>
<p>I changed my facebook password on another machine and i&#8217;m running a full system scan. Any other suggestions?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook trojan? by kitten</title>
		<link>http://gfreeman.wordpress.com/2009/09/03/facebook-trojan/#comment-3589</link>
		<dc:creator>kitten</dc:creator>
		<pubDate>Thu, 03 Sep 2009 22:12:00 +0000</pubDate>
		<guid isPermaLink="false">http://gfreeman.wordpress.com/?p=177#comment-3589</guid>
		<description>hi, I&#039;ve been keeping an eye on this tonight cause I was also caught out, by the looks of things it&#039;s just facebook information it&#039;s stealing, do you think there&#039;s any threat to our passwords for other sites?</description>
		<content:encoded><![CDATA[<p>hi, I&#8217;ve been keeping an eye on this tonight cause I was also caught out, by the looks of things it&#8217;s just facebook information it&#8217;s stealing, do you think there&#8217;s any threat to our passwords for other sites?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook trojan? by John Wilander</title>
		<link>http://gfreeman.wordpress.com/2009/09/03/facebook-trojan/#comment-3588</link>
		<dc:creator>John Wilander</dc:creator>
		<pubDate>Thu, 03 Sep 2009 21:19:37 +0000</pubDate>
		<guid isPermaLink="false">http://gfreeman.wordpress.com/?p=177#comment-3588</guid>
		<description>I rather think it&#039;s a cross-site request forgery than a cross-site scripting attack.

My take on this:
The suspicious site &#039;fastredbk&#039; knows that anyone accessing it is simultaneously logged on to Facebook since that&#039;s where the links are spread. fastredbk contains a request to facebook.com. That request will be issued in the victims browser, thus using the victim&#039;s Facebook account. The request is a one-click attack that sends notifications to all the victim&#039;s friends, attaching a link back to fastredbk.

Then of course fastredbk can contain various kinds of malware to exploit vulnerable browser plug-ins and such. So victims might well be compromised as well as spread the worm on to their friends.

As I said, the explanation above is just my guess.</description>
		<content:encoded><![CDATA[<p>I rather think it&#8217;s a cross-site request forgery than a cross-site scripting attack.</p>
<p>My take on this:<br />
The suspicious site &#8216;fastredbk&#8217; knows that anyone accessing it is simultaneously logged on to Facebook since that&#8217;s where the links are spread. fastredbk contains a request to facebook.com. That request will be issued in the victims browser, thus using the victim&#8217;s Facebook account. The request is a one-click attack that sends notifications to all the victim&#8217;s friends, attaching a link back to fastredbk.</p>
<p>Then of course fastredbk can contain various kinds of malware to exploit vulnerable browser plug-ins and such. So victims might well be compromised as well as spread the worm on to their friends.</p>
<p>As I said, the explanation above is just my guess.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook trojan? by Guy</title>
		<link>http://gfreeman.wordpress.com/2009/09/03/facebook-trojan/#comment-3587</link>
		<dc:creator>Guy</dc:creator>
		<pubDate>Thu, 03 Sep 2009 21:06:44 +0000</pubDate>
		<guid isPermaLink="false">http://gfreeman.wordpress.com/?p=177#comment-3587</guid>
		<description>Hi Michelle, thanks for your research. Reading the article, though, it doesn&#039;t strike me as the same phenomenon, because that required installing the rogue app. Here, unless I&#039;m mistaken (and John&#039;s story fits with this), only clicking on the rogue notification is required. Perhaps it&#039;s a cross-site scripting (XSS) attack?</description>
		<content:encoded><![CDATA[<p>Hi Michelle, thanks for your research. Reading the article, though, it doesn&#8217;t strike me as the same phenomenon, because that required installing the rogue app. Here, unless I&#8217;m mistaken (and John&#8217;s story fits with this), only clicking on the rogue notification is required. Perhaps it&#8217;s a cross-site scripting (XSS) attack?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook trojan? by Michelle</title>
		<link>http://gfreeman.wordpress.com/2009/09/03/facebook-trojan/#comment-3586</link>
		<dc:creator>Michelle</dc:creator>
		<pubDate>Thu, 03 Sep 2009 20:52:42 +0000</pubDate>
		<guid isPermaLink="false">http://gfreeman.wordpress.com/?p=177#comment-3586</guid>
		<description>After a little more poking around, I suspect that it&#039;s a new incarnation of &quot;rogue apps&quot; that were reported two weeks ago (first on Trend Micro and later on CNet News).  Here&#039;s an article from CNet about them: 
http://news.cnet.com/8301-27080_3-10313618-245.html</description>
		<content:encoded><![CDATA[<p>After a little more poking around, I suspect that it&#8217;s a new incarnation of &#8220;rogue apps&#8221; that were reported two weeks ago (first on Trend Micro and later on CNet News).  Here&#8217;s an article from CNet about them:<br />
<a href="http://news.cnet.com/8301-27080_3-10313618-245.html" rel="nofollow">http://news.cnet.com/8301-27080_3-10313618-245.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook trojan? by John Wilander</title>
		<link>http://gfreeman.wordpress.com/2009/09/03/facebook-trojan/#comment-3585</link>
		<dc:creator>John Wilander</dc:creator>
		<pubDate>Thu, 03 Sep 2009 20:49:19 +0000</pubDate>
		<guid isPermaLink="false">http://gfreeman.wordpress.com/?p=177#comment-3585</guid>
		<description>Hi! I&#039;m the Swedish guy who wrote about the what-I-presume-is-a Facebook worm.

It seems the bogus message links only appear in the notification meny in the lower right corner. The &quot;message&quot; never appears in the inbox.

The friend who unknowingly sent me the link told me he got a message himself, clicked it, ended up at a broken &quot;My photos&quot; page and closed it. In the mean time he had sent a bunch of links to his Facebook friends.

Seems like a CSRF that exploits a bug in the notification service.

/John</description>
		<content:encoded><![CDATA[<p>Hi! I&#8217;m the Swedish guy who wrote about the what-I-presume-is-a Facebook worm.</p>
<p>It seems the bogus message links only appear in the notification meny in the lower right corner. The &#8220;message&#8221; never appears in the inbox.</p>
<p>The friend who unknowingly sent me the link told me he got a message himself, clicked it, ended up at a broken &#8220;My photos&#8221; page and closed it. In the mean time he had sent a bunch of links to his Facebook friends.</p>
<p>Seems like a CSRF that exploits a bug in the notification service.</p>
<p>/John</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook trojan? by Michelle</title>
		<link>http://gfreeman.wordpress.com/2009/09/03/facebook-trojan/#comment-3584</link>
		<dc:creator>Michelle</dc:creator>
		<pubDate>Thu, 03 Sep 2009 19:41:50 +0000</pubDate>
		<guid isPermaLink="false">http://gfreeman.wordpress.com/?p=177#comment-3584</guid>
		<description>I got one today too; the icon looked like a gift but the notification was that I had a message.  When I saw that the address it was trying to load was not on Facebook, I stopped it immediately, so I don&#039;t know whether those php errors you report would have resolved for me.  Right now I&#039;m not finding anything about it other than this page, so it must be a new attack (presuming it&#039;s an attack, that is).</description>
		<content:encoded><![CDATA[<p>I got one today too; the icon looked like a gift but the notification was that I had a message.  When I saw that the address it was trying to load was not on Facebook, I stopped it immediately, so I don&#8217;t know whether those php errors you report would have resolved for me.  Right now I&#8217;m not finding anything about it other than this page, so it must be a new attack (presuming it&#8217;s an attack, that is).</p>
]]></content:encoded>
	</item>
</channel>
</rss>
