On MovieTome: Why you didn't see Shatner in TREK
BNET Business Network:
BNET
TechRepublic
ZDNet

October 31st, 2008

Spammers targeting Bebo, generate thousands of bogus accounts

Posted by Dancho Danchev @ 11:13 am

Categories: Phishing, Social Networking Applications, Spam and Phishing, Web 2.0

Tags: Security, CAPTCHA, Bebo, Social Networking, Dancho Danchev

Bebo CAPTCHA SpamThe concept of building a fraudulent ecosystem by abusing legitimate services only is nothing new, and as we’ve already seen numerous times throughout the year, malicious attackers are actively embracing it. Bebo, the popular social networking site is currently under attack from spammers that are automatically registering thousands of bogus accounts advertising fake online pharmacies, with the campaign owners receiving revenue through an affiliate based program. The automated registration process is made possible through breaking Bebo’s CAPTCHA in a combination with using bogus email registered in the very same fashion. This isn’t the first time Bebo has been targeted by spammers, and definitely not the last.

“Interestingly, spammers have found other uses for the valid email addresses created on sites such as MobileMe (mac.com), by linking these addresses to accounts created on social networking sites, such as Bebo. As can be seen below, a search on Google for Cialis, a drug commonly referenced in spam messages, reveals two accounts on Bebo in the top-five results returned.

Consequently, users of social networking sites are receiving more “buddy” requests from fake profiles wishing to connect. This approach works well because traditional anti-spam solutions are unable to differentiate between these requests and genuine ones. The buddy requests appear genuine as they are from the real social networking site and consequently their headers are intact and correct. Moreover, the email addresses attached to the profiles are also valid, albeit they have been created fraudulently. Often, the only visible clues may sometimes be the random arrangement of letters in the user name portion of the email address.”

Bebo CAPTCHA SpamApproximately 30,000 bogus profiles have been generated for October alone. Why Bebo at the first place? As always, Bebo isn’t targeted exclusively, but in between other social networking sites and blogging platforms, since from a blackhat search engine optimization perspective, the more popular the abused service the higher the visibility and shorter the timeframe for search engine crawlers to pick up their bogus content. The potential for abuse here is enormous, since once the profiles start acquiring traffic, the spammers could and will easily start selling the traffic through a traffic exchange program created exclusively for malicious purposes like redirecting to live exploit URLs, and rogue security software.

Direct CAPTCHA breaking or outsourcing the process to humans in order to make such spam campaigns across social networking sites possible, is only going to get more efficient in 2009.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 5 Talkback(s)
Sounds Good to me
Double opt in is the way to go. If Bebo is afraid too many users will be scared by that SMALL extra effort to sign-up, then they do NOT have a useful business model.

It really is that simple.... (Read the rest)
Posted by: mejohnsn Posted on: 12/12/08 You are currently: a Guest | | Terms of Use
Your site gets overwhelmed then it's gone  BALTHOR | 10/31/08
The imaginary economy of the Internet  terry flores | 11/01/08
RE: Spammers targeting Bebo, generate thousands of bogus accounts  TheBrainchildGroup | 11/01/08
May need to rethink automatic sign ups  mystic100 | 11/03/08
Sounds Good to me  mejohnsn | 12/12/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and