Anatomy Of Self-Inflicted Javascript Injection On Facebook
ID: 765ba958-5aa6-52a1-8bde-ef2840c5d26c
STIX ID: report--765ba958-5aa6-52a1-8bde-ef2840c5d26c
Feed Name: Zscaler Security Research Blog
This report explains a Facebook abuse campaign that uses self-inflicted JavaScript injection (users copying/pasting JS into the browser URL bar) to perform actions on victims' accounts—auto-liking content, sending invites/messages to all friends, and distributing malicious or offensive links (examples include hex-encoded scripts and bit.ly redirects to facebook.joyent.us hosts). It describes the technique, demonstrates sample payloads, and warns users about the risks of running arbitrary JS in their browser address bar.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
