Heykuki News

TopNewBestAskShowJobs
TopNewBestAskShowJobs
Ask.fm malicious javascript (also contains Facebook and Twitter)
2 points
tarikozket
14 years ago
hi,

I just opened source code of ask.fm last night and saw so many malicious javascript codes are there.

here is the screenshot of ask.fm source code right now : http://i.imgur.com/MdzV7.png

here is the pastebin of ask.fm source code right now : http://pastebin.com/a2zv2SnR

and I investigated the sitution little bit more and realized it happens only(maybe other countries too, idk) when you enter the page from Turkey, because there wasn't any javascript code when I tried with "anonymouse.org" and javascript file names are Turkish.

http://www.tavascript.com/antivirus/script.js / pastebin : http://pastebin.com/fqPhJYcg

http://www.tavascript.com/antivirus/js/ask.js / giving 404, probably referrer is wrong

http://www.autoliked.net/antivirus/script.js / 500 gateway error

http://www.otodurumbegen.com/calistir/js/sd.php / pastebin : http://pastebin.com/3et3SPXy

http://eklentim.com/app/askfm.js / pastebin : http://pastebin.com/5burnVi9

https://www.twtakipcikazan.com/cekimler/fb/like.php / pastebin : http://pastebin.com/s6Pr6iPy

https://www.twtakipcikazan.com/takip/js/script.js / pastebin : http://pastebin.com/XC9nFHNj

https://www.twtakipcikazan.com/cekimler/ask/ask.php / pastebin : http://pastebin.com/2XCPej0B

https://www.twtakipcikazan.com/cekimler/fb/facebook.php / pastebin : http://pastebin.com/EY8w0dvq

It's so weird and dangerous. My scenario is one of translator guys wrote this lines to there, maybe.

If there is somebody from ask.fm, facebook or twitter :

hey ask.fm guy : your website containing malicious javascript code, take care about it and be careful next time!

hey facebook guy : In javascript files there are page id's and profile id's which are fake, take care about it!

hey twitter guy : In javascript files there are twitter account id's which are fakely followed by people, take care about it!