<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Fortinet Security Blog &#187; facebook</title>
	<atom:link href="http://blog.fortinet.com/tag/facebook/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fortinet.com</link>
	<description>Real Time Network Protection</description>
	<lastBuildDate>Fri, 27 Jan 2012 11:59:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
	<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Fortinet Product Marketing </copyright>
		<managingEditor>rpopko@fortinet.com (Fortinet Product Marketing)</managingEditor>
		<webMaster>rpopko@fortinet.com(Fortinet Product Marketing)</webMaster>
		<category>Fortinet Product Information</category>
		<ttl>1440</ttl>
		<itunes:keywords>forti-gate, anti-spam, anti-virus, fortigate</itunes:keywords>
		<itunes:subtitle>The latest news and information about Fortinet products and services for Real Time Network Protection.</itunes:subtitle>
		<itunes:summary>Fortinet is a leading provider of Unified Threat Management (UTM) network security solutions for enterprise and service provider environments. The Fortinet FortiCast delivers news, information, and tutorials about products, services, and industry trends. Fortinet's FortiGate product line and FortiGuard security subscription services provide an array of integrated network security functions including antivirus, firewall, virtual private networking, intrusion prevention (IPS), web filtering, antispam and traffic optimization. </itunes:summary>
		<itunes:author>Fortinet Product Marketing</itunes:author>
		<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Tech News"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Fortinet Product Marketing</itunes:name>
			<itunes:email>rpopko@fortinet.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-300x300.jpg" />
		<image>
			<url>http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-144x144.jpg</url>
			<title>Fortinet Security Blog</title>
			<link>http://blog.fortinet.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>For your ease of following us: Facebook &amp; Twitter</title>
		<link>http://blog.fortinet.com/fortiguard-labs-are-on-facebook-twitter/</link>
		<comments>http://blog.fortinet.com/fortiguard-labs-are-on-facebook-twitter/#comments</comments>
		<pubDate>Mon, 20 Jun 2011 10:31:33 +0000</pubDate>
		<dc:creator>Ruchna Nigam</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[feed]]></category>
		<category><![CDATA[fortiguard labs]]></category>
		<category><![CDATA[security research]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3071</guid>
		<description><![CDATA[A couple of days back, a game of Nerd Truth or Dare in the lab led to the shocking revelation that most of us were using our Facebook/Twitter accounts mainly to keep up with security blogs. Personally, being a twitter non-conformist until recently, I even created a twitter account for this sole purpose. And that [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of days back, a game of Nerd Truth or Dare in the lab led to the shocking revelation that most of us were using our Facebook/Twitter accounts mainly to keep up with security blogs. Personally, being a twitter non-conformist until recently, I even created a twitter account for this sole purpose. And that led to the realization that FortiGuard Labs need to &#8216;get with it&#8217; too.</p>
<p>So here&#8217;s introducing our <a href="https://www.facebook.com/home.php#!/pages/FortiGuard-Labs/228520810496253?sk=wall">Facebook</a> and <a href="https://twitter.com/#!/FortiGuardLabs">Twitter</a> pages for your ease of following us.</p>
<p>If you, like us, have tried every RSS aggregator there is under the sun, have been left unsatisfied with each, and then have finally resorted to using social networks as aggregators, you might be happy to know that you can follow FortiGuard Labs through your Twitter or Facebook accounts.</p>
<p>Follow/Like us to keep up with our research, blog posts, threat advisories and other work that we feel you might find interesting.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/fortiguard-labs-are-on-facebook-twitter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Encrypting Facebook</title>
		<link>http://blog.fortinet.com/encrypting-facebook/</link>
		<comments>http://blog.fortinet.com/encrypting-facebook/#comments</comments>
		<pubDate>Tue, 21 Dec 2010 16:36:12 +0000</pubDate>
		<dc:creator>Axelle</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[firegpg]]></category>
		<category><![CDATA[gpg]]></category>
		<category><![CDATA[passphrase]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=2033</guid>
		<description><![CDATA[A while ago, probably after a long and difficult day, I got into this funny idea of encrypting my Facebook account messages so that only the people I really wanted to could read them...]]></description>
			<content:encoded><![CDATA[<p>A while ago, probably after a long and difficult day, I got into this funny idea of encrypting my Facebook account messages so that only the people I really wanted to could read them (i.e not an unknown stranger using <a href="http://en.wikipedia.org/wiki/Firesheep">Firesheep</a>, nor a third-party applications or not even Facebook itself). For a moment, I wondered how to do this, until I remembered a Firefox plugin named <a href="http://firegpg.tuxfamily.org/">FireGPG</a>. Basically, FireGPG is Firefox extension to GPG, i.e it enables easy encryption/ decryption/ signature/ and verification in the browser.</p>
<p>So, I installed the plugin and tried it out. It&#8217;s quite easy to use, actually. I prepared a new message in Facebook (don&#8217;t hit the &#8220;share&#8221; button yet). The example below shows the encryption of a new status, but of course, it works just the same with direct user to user messages.</p>
<p style="text-align: center;"><a href="http://blog.fortinet.com/wp-content/uploads/2010/12/justtrying.jpg"><img class="aligncenter size-full wp-image-2034" title="Writing an encrypted status message on Facebook" src="http://blog.fortinet.com/wp-content/uploads/2010/12/justtrying.jpg" alt="Writing an encrypted message on Facebook" width="529" height="133" /></a></p>
<p>Then, I encrypted the message (copy message to clipboard and do Tools &gt; FireGPG &gt; Encrypt &#8211; for example) I wanted to secure. FireGPG is basically a GPG front-end, so it is possible to use public key cryptography and encrypt the message for one or several recipients (provided their public keys are in your keyring) or use &#8220;conventional encryption&#8221; which consists in sharing a passphrase among recipient.</p>
<p>This is what my wall looks like to unsollicited readers or applications :) Geeky, huh ?</p>
<p style="text-align: center;"><a href="http://blog.fortinet.com/wp-content/uploads/2010/12/firegpg-encrypted.jpg"><img class="aligncenter size-full wp-image-2035" title="Encrypted message on Facebook" src="http://blog.fortinet.com/wp-content/uploads/2010/12/firegpg-encrypted.jpg" alt="Encrypted message on Facebook" width="538" height="170" /></a></p>
<p>But friends whom the message is for (and who have FireGPG installed) can decrypt this quite easily, because the FireGPG plugin spots there is an encrypted message and displays the following:</p>
<p style="text-align: center;"><a href="http://blog.fortinet.com/wp-content/uploads/2010/12/firegpg-todecrypt.jpg"><img class="aligncenter size-full wp-image-2036" title="FireGPG spots an encrypted message" src="http://blog.fortinet.com/wp-content/uploads/2010/12/firegpg-todecrypt.jpg" alt="FireGPG spots an encrypted message" width="562" height="134" /></a></p>
<p>They click on decrypt, enter their keyring passphrase or the shared passphrase, and read my wall correctly.</p>
<p style="text-align: center;"><a href="http://blog.fortinet.com/wp-content/uploads/2010/12/firegpg-decrypted.jpg"><img class="aligncenter size-full wp-image-2037" title="Decrypted message" src="http://blog.fortinet.com/wp-content/uploads/2010/12/firegpg-decrypted.jpg" alt="Decrypted message" width="539" height="156" /></a></p>
<p>Note that if you are already using a Firefox plugin such as <a href="https://www.eff.org/https-everywhere">HTTPS everywhere</a> or <a href="http://https://addons.mozilla.org/en-US/firefox/addon/12714/">Force-TLS</a>, the communication pipe with Facebook (from your browser to Facebook hosts) is already secure, thus FireSheep users (and sniffers in general) won&#8217;t be able to snoop on your private data. In that case, FireGPG is &#8216;only&#8217; useful to secure the messages on Facebook hosts &#8211; in other words, if you want that Facebook itself cannot read them (nor anyone else hacking her way into it).</p>
<p>Okay, so now I need to convert my friends to FireGPG. ;)</p>
<p>&#8211; the Crypto Girl</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/encrypting-facebook/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Spam 2.0 leads Facebook users to Canadian Pharmacy ring</title>
		<link>http://blog.fortinet.com/facebook-spam-canadian-pharmacy/</link>
		<comments>http://blog.fortinet.com/facebook-spam-canadian-pharmacy/#comments</comments>
		<pubDate>Mon, 04 May 2009 20:01:46 +0000</pubDate>
		<dc:creator>GLovet</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[spam 2.0]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=298</guid>
		<description><![CDATA[Our sensors (i.e. our digital media person, a rabid fan of Facebook) caught today some interesting Facebook private messages. One of such, sent by a &#8220;Friend&#8221; to about 100 contacts of hers, merely consisted in a domain name, as can be seen below: Fortunately for Daniel, he did not know what to do with it [...]]]></description>
			<content:encoded><![CDATA[<p>Our sensors (i.e. our digital media person, a rabid fan of Facebook) caught today some interesting Facebook private messages. One of such, sent by a &#8220;Friend&#8221; to about 100 contacts of hers, merely consisted in a domain name, as can be seen below:</p>
<p><img class="size-full wp-image-299 alignnone" title="facebook_spam" src="http://blog.fortinet.com/wp-content/uploads/2009/05/facebook_spam.jpg" alt="Mass Private Message" width="524" height="360" /></p>
<p>Fortunately for Daniel, he did not know what to do with it (or he knew, but did not want to); yet other recipients may have recognized a domain name, and entered it in their browser&#8217;s address bar, out of curiosity. After all, that&#8217;s from Martha, and she usually sends rather funny links.</p>
<p><img class="alignleft size-full wp-image-301" title="female_cialis" src="http://blog.fortinet.com/wp-content/uploads/2009/05/female_cialis.jpg" alt="female_cialis" />Of course, the link was not actually from Martha, but rather from a cyber criminal having compromised her account. Fortunately, unlike Martha feared (but one is never too careful, and Martha is wise), the link did not lead to a virus-loaded page, but to a &#8220;pharmacy shop&#8221; belonging to the infamous &#8220;<a href="http://www.fortiguardcenter.com/analysis/canadianpharmacy.html" target="_blank">Canadian Pharmacy Ring</a>&#8220;, and registered at &#8220;Directi Internet Solutions&#8221; (the new name of the infamous EST Domains registrar). In a nutshell, a typical case of spam 2.0. But while <a href="http://www.fortiguardcenter.com/advisory/FGA-2008-08.html" target="_blank">spamvertizement has happened before on Facebook Walls</a>, and worms such as <a href="http://www.fortiguardcenter.com/advisory/FGA-2008-26.html">Koobface did leverage Facebook Private Messages to propagate</a>, to our knowledge it&#8217;s the first instance of spam being distributed via Facebook Messages.</p>
<p>Another point worth mentioning is that while to Daniel&#8217;s eyes (if we assume his reply was ironic), junglemix.in was obviously a domain name, it was not at all the case to Facebook filters. We have shown in a previous post how <a href="http://blog.fortinet.com/facebook-url/" target="_blank">Facebook wraps all urls featured in messages</a>, so as to retain control on the &#8220;clicks&#8221; performed by recipients, even if those recipients read the message from their regular email account. This one obviously went under the radar, most likely because it did not feature &#8216;http://&#8217;, &#8216;www&#8217;, and used a domain extension (.in) that is also a (very) common word.</p>
<p>The consequence is that although Facebook did react fast, deleting the messages in the Facebook boxes, those which have already reached the regular mailboxes of recipients (most people do have the &#8220;forward messages to my email&#8221; option enabled), are still there, unwrapped, so Facebook cannot deny access to the link. The downside for criminals, of course, is that it is not clickable.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/facebook-spam-canadian-pharmacy/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Facebook&#8217;s automatic URL-wrapping: A double-edged sword?</title>
		<link>http://blog.fortinet.com/facebook-url/</link>
		<comments>http://blog.fortinet.com/facebook-url/#comments</comments>
		<pubDate>Thu, 05 Mar 2009 22:13:54 +0000</pubDate>
		<dc:creator>GLovet</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[open redirector]]></category>
		<category><![CDATA[url redirection]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=173</guid>
		<description><![CDATA[The Koobface worm scouring Facebook since last July, and which made the headlines again this week, is certainly beginning to redesign the concept of &#8220;friend. &#8221; The &#8220;acquaintance from high school you&#8217;ve never talked to since you added her/him&#8221; might now be the &#8220;acquaintance from high school you&#8217;ve never talked to since you added her/him [...]]]></description>
			<content:encoded><![CDATA[<p>The Koobface worm scouring <a href="http://www.facebook.com">Facebook</a> since last July, and which made the <a href="http://blogs.pcmag.com/securitywatch/2009/03/new_koobface_variant_preys_on.php">headlines again this week</a>, is certainly beginning to redesign the concept of &#8220;friend. &#8221; The &#8220;acquaintance from high school you&#8217;ve never talked to since you added her/him&#8221; might now be the &#8220;acquaintance from high school you&#8217;ve never talked to since you added her/him and who occasionally sends links to sites loaded with viruses.&#8221;</p>
<p>While Koobface has redefined this friendship concept, it&#8217;s not the only thing: It&#8217;s redefined the URL redirection policy of Facebook.</p>
<p>Indeed, URLs used to be left &#8220;as is&#8221; in friends&#8217; private messages &#8212; assuming that they did not lead to a malicious site, of course. This is the very reason why Koobface &#8220;first-click URLs&#8221; are a mere hop through a reputable site (<a href="http://www.fortiguardcenter.com/advisory/FGA-2008-26.html">Google Reader, Google Picasa&#8230;</a>), which in turns redirect unfortunate users to the final, malicious site (Facebook is not going to blacklist Google, right?).</p>
<p>Now and then, URLs included in messages are being automatically wrapped up by Facebook, in the following fashion:</p>
<p><strong>URL:</strong> http://www.example.com<br />
<strong>Wrapped URL</strong>: http://www.facebook.com/l.php?u=http://www.example.com</p>
<p>The latter is called a &#8220;web redirector.&#8221; Upon clicking on the wrapped URL, users are &#8220;going through&#8221; Facebook before reaching the final destination (here, www.example.com). What is really the point in force-wrapping URLs in redirectors? Simple: Friends&#8217; messages are not only sent to the recipient Facebook account within the site, but are also e-mailed to the recipient external mailbox (Gmail, Hotmail, Yahoo Mail, etc.). Wrapping URLs in redirectors therefore allows Facebook to track clicks even when they are performed from the recipient external mailbox.</p>
<p>In our precise case, this serves a security purpose: even once malicious messages have been successfully emitted, users happily journeying toward the malicious final site from their mailbox can still be stopped at the redirector level.</p>
<p>It does make <em>some</em> sense. One may very well wonder if the cure is not worse than the disease, however. Indeed, web redirectors raise multiple security issues, which have been <a href="http://seclists.org/fulldisclosure/2003/Mar/0200.html">known since at least 2003</a> and have many times <a href="http://www.surbl.org/redirect.html">generated indignation in the ranks</a> of the security industry.</p>
<p>Simply put, open web redirectors allow spammers, phishers, fraudsters, scammers and other cyber criminals to &#8220;wash&#8221; their malicious links with the name of a reputable site, fooling URI filters and human users alike.</p>
<p>Indeed, wouldn&#8217;t http://www.facebook.com/l.php?u=http://my%2Emalicious%2Esite%2Ecom be more likely to be trusted than http://my.malicious.site.com? This is where it all becomes ironic: since precisely this redirector is meant to wrap malicious links, Facebook might be seen as unwillingly giving an edge to cyber criminals without the later ones even being aware of it.</p>
<p>Granted, when going through Facebook redirector, users are presented a message stating:</p>
<p style="padding-left: 30px;">&#8220;You are about to leave Facebook to visit this address: [...] For the safety and privacy of your Facebook account, remember to never enter your password unless you&#8217;re on the real Facebook web site.&#8221;</p>
<p>Let&#8217;s therefore grant Facebook&#8217;s the title of &#8220;semi-open redirector.&#8221; Yet, users are nowadays so much watered by warnings anywhere they click, that the efficiency of this one may be questioned. Besides, a base of social engineering (directly inherited from experimental social psychology) is that once the decision to perform the first click has occured, little events could reverse the process of commitment to reaching the destination.</p>
<p>So, automatic URL-wrapping, a good idea or a double-edged sword forced by Koobface&#8217;s pressure?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/facebook-url/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>

