Last Comment Bug 754648 - Malicious Facebook - "Remove My Timeline" add-on
: Malicious Facebook - "Remove My Timeline" add-on
Status: RESOLVED FIXED
:
Product: Toolkit
Classification: Components
Component: Blocklisting (show other bugs)
: unspecified
: All All
: -- normal (vote)
: ---
Assigned To: Jorge Villalobos [:jorgev]
:
: Jorge Villalobos [:jorgev]
Mentors:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-05-13 01:17 PDT by Mark Wolf
Modified: 2016-03-07 15:30 PST (History)
7 users (show)
See Also:
Crash Signature:
(edit)
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---


Attachments

Description Mark Wolf 2012-05-13 01:17:29 PDT
User Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.66 Safari/535.11

Steps to reproduce:

I entered: http://removemytimeline.com/
Thinking its a facebook web site that will remove my facebook time line.
It made me install this file:
http://removemytimeline.com/remove_my_timeline.xpi

http://removemytimeline.com/remove_my_timeline.crx



Actual results:

It started to spam my my wall, friends wall, inbox, etc - sharing with bitly.com short link the web site http://removemytimeline.com/ all without your knowledge or consent every few minutes.

My friend wall:
http://i.imgur.com/IAxLt.jpg
My wall:
http://i.imgur.com/UECRP.jpg

Also I noticed that it spying after me and after everyone who installed this add-on by running in the background:
http://whos.amung.us/swidget/googlestatic.gif
http://whos.amung.us/stats/googlestatic/ - Show the actual stats.

It should not post Facebook messages, sharing or like pages without your knowledge or consent.



Expected results:

It should have remove my time line only.
Comment 1 Jorge Villalobos [:jorgev] 2012-05-14 14:12:48 PDT
Id: crossriderapp4926@crossrider.com
Comment 2 Jorge Villalobos [:jorgev] 2012-05-14 14:28:07 PDT
Blocked: https://addons.mozilla.org/en-US/firefox/blocked/i91
Comment 3 James 2012-05-15 08:05:33 PDT
(In reply to Mark Wolf from comment #0)
> User Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.11 (KHTML, like
> Gecko) Chrome/17.0.963.66 Safari/535.11
> 
> Steps to reproduce:
> 
> I entered: http://removemytimeline.com/
> Thinking its a facebook web site that will remove my facebook time line.
> It made me install this file:
> http://removemytimeline.com/remove_my_timeline.xpi
> 
> http://removemytimeline.com/remove_my_timeline.crx
> 
> 
> 
> Actual results:
> 
> It started to spam my my wall, friends wall, inbox, etc - sharing with
> bitly.com short link the web site http://removemytimeline.com/ all without
> your knowledge or consent every few minutes.
> 
> My friend wall:
> http://i.imgur.com/IAxLt.jpg
> My wall:
> http://i.imgur.com/UECRP.jpg
> 
> Also I noticed that it spying after me and after everyone who installed this
> add-on by running in the background:
> http://whos.amung.us/swidget/googlestatic.gif
> http://whos.amung.us/stats/googlestatic/ - Show the actual stats.
> 
> It should not post Facebook messages, sharing or like pages without your
> knowledge or consent.
> 
> 
> 
> Expected results:
> 
> It should have remove my time line only.

there is nothing wrong with this addon me and my friends have been using it it's no scam nothing at all wrong with it most people hate the facebook updates they hate the timeline this is an amazing addon now unblock it!
Comment 4 Mark Wolf 2012-05-27 02:03:22 PDT
(In reply to Jorge Villalobos [:jorgev] from comment #2)
> Blocked: https://addons.mozilla.org/en-US/firefox/blocked/i91

www.removemytimeline.com/remove_my_timeline.xpi is working again, they have changed the id.
Comment 5 Jorge Villalobos [:jorgev] 2012-05-28 08:49:58 PDT
If they changed their id and they are doing anything malicious, please file a separate bug.

Note You need to log in before you can comment on or make changes to this bug.