Curiosity (about other people's secrets) can be a deadly sin in the world of social networking, too. This flaw is exploited by would-be digital land grabbers on Facebook. They send instructions promising to open the door wide to anyone else's house on Facebook. In reality, by following the instructions, you are giving them the keys to yours.
The deceptive message is titled “Hack any facebook account following three steps” (or similar) and comes either via email or as a post on the timeline of a Facebook friend who has already fallen victim to the scam. It urges the recipient to open their Internet browser and log in to the Facebook page of the person they want to hack. They are then asked to right-click anywhere on the page and select “Inspect element”, which opens a window in the lower half of the browser for editing the HTML. The malicious instructions invite the user to copy and paste code, which supposedly would grant access to the current profile. Instead, it does so for their own account, not the one they indicated.
This is the so-called cross-site scripting (XSS), a method by which a commonly considered security flaw in the browser is exploited - the ability to insert code into a web page.
Facebook refers to this type of scam as Self-XSS and describes it as a sequence of actions that trick members into granting access to their account. The attackers gain posting, commenting, and other privileges.
“Attackers who use Self-XSS usually trick you into promising to help you compromise someone else’s account. The attacker’s goal is to get you to run their malicious code on your computer. When you run the attacker’s code, you give them access to your account for fraud, misleading content, and, most importantly, you give them the ability to trick more people into running the malicious code. Attackers usually target your friends by posting to your Timeline. To avoid Self-XSS attacks, never copy and paste suspicious links,” the service’s report concludes.
It is also important that you mark the post you see among your friends' posts as Spam to limit the spread of the scam and the number of potential victims.
Source: tech.in.gr

