Friday, June 14, 2013

On The Facebook Spammy App Which Tags All You In A Stupid Photo - the how and the why - Part 1

I have blogged about facebook spam app before. Quite some time has passed without me noticing anything other stupid spam in my feed, but recently I've been seeing quite a lot of activity from one particular app which tags a lot of people in a naughty picture which appears to be a video.

So if you were tagged in a stupid spammy picture recently read on to see how your perverted friends got fooled. (And fix your privacy settings - you share part of the blame too)

The picture appears to be a youtube clip, and the thumbnail signals the viewer that they might get to see something, y'all know...

The hapless pervert clicks on it, and off we go this page (

(Ok now I should not have been so judgmental earlier, the words here seem fine :P )

Once again the player is just a picture. It looks like a flash player, but it isn't. Now your friend has clicks on the play button, again..

 A tiny new window opens, and the original page is updated with instructions to copy the URL from the other window, and then comes the shocker,

Its freaking asking you to paste the URL - ctrl + C and ctrl + V, goodness great, and people still do it??? (Two of my friends did - I'm never going to trust them with anything on the internet, ever)

What just happened was - they just granted the app the permission to tag their friends - just by proving that they are, human (no, I disagree, they are monkeys).

Here is the URL they pasted view-source:

You can find -

the app's API key - 139682082719810,

In the &next= you can see the facebook URL for requesting permission.

If you want to see what's going on under the hood please go on to part 2.

No comments:

Post a Comment