Social Networking Porn Shocker

newsguy 1 Tallied Votes 513 Views Share

According to the latest State of Spam and Phishing from Symantec, a truly astonishing 92% of all adult phishing scams are being conducted across social networking sites. This coincides with a newly identified trend of adult oriented phishing whereby users are being tempted to enter personal credentials in exchange for the promise of free porn. A new trend using a very old premise, it would seem, as I recall the same 'free porn' promise being made over the years with scams ranging from Trojan Porn Diallers to drive by malware delivery. Indeed, the new trend is very similar to those attack vectors of old when you look at the payload: users are directed to a porn site which in turn leads to fake antivirus sites (most often using the pop-up alert trick) which contain malicious code. Most of the phishing sites involved have been created using free web hosting services.

Symantec warns that both scam and phishing categories have doubled as a percentage of all spam in January 2010 compared to December 2009. Even good old 419-Nigerian spam has had something of a resurrection with this particular type of scam accounting for 21% of all spam - the highest level recorded since Symantec started publishing its report.

Dani AI

Generated

Useful, practical follow‑up to the points raised by and . The pattern described — enticing links on social sites that chain into scareware or credential capture, often hosted on throwaway webspace — is classic social‑engineering plus a lightweight technical redirect. Below are concise, actionable steps for victims and for people running or moderating social properties.

For users (quick triage and prevention):

  • If you clicked a link but didn’t log in or install anything: log out of the social site, clear the browser cache/cookies, and change passwords only from a known‑clean device.
  • If you entered credentials: change that password immediately (from another device), enable two‑factor authentication, and check connected apps/sessions for unauthorized access.
  • If a page prompted you to download “antivirus” or an executable: do not run it. Disconnect, boot into safe mode (or a rescue disk), and run a reputable offline scanner; if removal fails, restore from backups or reinstall.
  • Learn to inspect links before clicking: preview on mobile (long‑press), hover/copy on desktop, and watch for extra subdomains, misspellings or URL shorteners that hide destinations.

For social platform owners and marketers:

  • Treat sudden, thematic bursts (e.g., “private video” posts) as high‑risk. Apply automated URL reputation checks, block known malicious hosts, and throttle accounts that send many identical messages.
  • Provide easy, visible “report link” actions and automated warnings for links that redirect through unfamiliar hosts.
  • Educate users with brief inline tips (how to preview links, enable 2FA) rather than long policy pages.

Final note: social engineering succeeds on curiosity. Quick hygiene — don’t install unsolicited software, use unique passwords plus 2FA, and verify links — prevents the majority of these scams.

InsightsDigital 57 Posting Virtuoso

Spammers had to think of innovative ways to spam people since the Nigerian plea email, AOL, and Paypal phishing is old news.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.