{"id":9112,"date":"2017-09-06T08:10:14","date_gmt":"2017-09-06T16:10:14","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/09\/06\/news-2885\/"},"modified":"2017-09-06T08:10:14","modified_gmt":"2017-09-06T16:10:14","slug":"news-2885","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/09\/06\/news-2885\/","title":{"rendered":"Facebook worries: I didn\u2019t post that"},"content":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Wed, 06 Sep 2017 15:00:12 +0000<\/strong><\/p>\n<p>It is my assumption that most Facebook users don\u2019t look at their own profile often. With your own profile, I mean the timeline that shows up when you click your own name or avatar in the Facebook menu.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-19530\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/ownprofile.png\" alt=\"profile menu\" width=\"477\" height=\"53\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/ownprofile.png 477w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/ownprofile-300x33.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/ownprofile-470x53.png 470w\" sizes=\"auto, (max-width: 477px) 100vw, 477px\" \/><\/p>\n<p>That\u2019s because we <em>think<\/em> we know exactly what is posted there, so why bother to look at it? After all, isn\u2019t that supposed to be all the stuff that we posted ourselves?<\/p>\n<p>The feeling of disorientation you get when you find something you are sure you <em>didn&#8217;t<\/em> post will be even worse if you notice that supposed messages have been <a href=\"https:\/\/thehackernews.com\/2017\/08\/facebook-virus-hacking.html\" target=\"_blank\" rel=\"noopener\">sent from your Facebook Messenger account<\/a> that you know you never sent. All in all, there might be some discrepancies between what you did and what actually shows up and that\u2019s what this blog post is all about.<\/p>\n<h3>How do posts end up on your timeline that you didn&#8217;t post?<\/h3>\n<p>There are three main reasons that might be of some concern:<\/p>\n<ol>\n<li>Someone or something else has access to your Facebook account<\/li>\n<li>A Facebook app has the authorization to post on your timeline<\/li>\n<li>An active script or browser extension can post on your behalf<\/li>\n<\/ol>\n<p>In all these cases, there is no immediate reason to worry as long as you know about it and trust the person, app, script, or extension that has access or authorization.<\/p>\n<h3>Authorized apps<\/h3>\n<p>We have seen it the past and I bet there are still active apps being spread among Facebook users by pretending to be spectacular videos. You may remember the \u201cMan found inside Shark\u201d and similar sensational posts, which try to trick you into downloading malware or installing a malicious app.<\/p>\n<p>To check whether an app has the ability to post on your timeline, click on Settings:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-19533 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/settings.png\" alt=\"Facebook settings\" width=\"249\" height=\"384\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/settings.png 249w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/settings-195x300.png 195w\" sizes=\"auto, (max-width: 249px) 100vw, 249px\" \/><\/p>\n<p>On the left-hand side, click on Apps and select any app that doesn&#8217;t look familiar or trustworthy. You can see whether they can post on your timeline by looking at their permissions. If they have the authorization to post on your timeline, it will look like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-19531\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/post.png\" alt=\"post permission\" width=\"611\" height=\"163\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/post.png 611w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/post-300x80.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/post-600x160.png 600w\" sizes=\"auto, (max-width: 611px) 100vw, 611px\" \/><\/p>\n<p>Delete apps you don\u2019t trust or no longer use by clicking on the <em>X<\/em> that shows up when you hover over an app with your mouse pointer in the Apps menu.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-19535 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/removeapp.png\" alt=\"remove app\" width=\"348\" height=\"91\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/removeapp.png 348w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/removeapp-300x78.png 300w\" sizes=\"auto, (max-width: 348px) 100vw, 348px\" \/><\/p>\n<h3>Scripts posting on your behalf<\/h3>\n<p>It is possible there is an active script (or program) that uses your credentials when you have Facebook opened in your browser. The script does not need to log in, but simply makes use of the fact that you already did log in. It doesn&#8217;t matter whether you did that actively or whether you relied on a cookie set in an earlier session.<\/p>\n<p>These scripts can be hiding in your browser cache or in the shortcut that you use to open Facebook. You can find localized and browser-specific help on clearing your cache on this <a href=\"https:\/\/www.facebook.com\/help\/1416643995215690\" target=\"_blank\" rel=\"noopener\">Facebook Help page<\/a> for several browsers. You can circumvent using your shortcuts if you suspect they have been altered by typing <em>facebook.com<\/em> in your browsers address bar. Once you are sure the shortcuts have been altered, you can find methods on\u00a0<a href=\"https:\/\/forums.malwarebytes.com\/topic\/85715-faq-malwarebytes-wont-run-or-failed-to-resolve-my-issues\/\" target=\"_blank\" rel=\"noopener\">how to clean your browser shortcuts<\/a> on our forums.<\/p>\n<p>Browser extensions could be responsible for this similar behavior. They can be removed following these procedures:<\/p>\n<ul>\n<li>Internet Explorer: Tools (gear icon) &gt; Manage add-ons &gt; Toolbars and Extensions &gt; Select the one(s) you don\u2019t trust one by one and click \u201cDisable\u201d<\/li>\n<li>Firefox: Menu (horizontal stripes) &gt; Add-ons &gt; click on \u201cDisable\u201d behind the ones you don\u2019t trust or don\u2019t recall installing.<\/li>\n<li>Chrome: Menu (3 dots) &gt; More Tools &gt; Extensions &gt; Uncheck \u201cEnabled\u201d behind the ones you don\u2019t trust or don\u2019t recall installing.<\/li>\n<li>Opera: click the Opera icon &gt; Extensions &gt; Extension Manager &gt; click on Disable below the ones you don\u2019t trust or don\u2019t recall installing.<\/li>\n<\/ul>\n<h3>Stolen credentials<\/h3>\n<p>I\u2019m posting about this as the last option for a reason as the advice that we will give you here does not only apply to the cases where you know that someone or something you didn\u2019t authorize posted on your behalf. If you have experienced or suspected that something or someone has been posting without your knowledge, or one of the other options (scripts, rogue apps), we recommend that you change your password and <a href=\"https:\/\/www.facebook.com\/help\/148233965247823\" target=\"_blank\" rel=\"noopener\">enable 2FA<\/a>, if you haven\u2019t already. Even if you have no idea who might have been responsible, we recommend you lock them out before they abuse their access to your account even further. We also recommend doing this even if you found out which app or other method was used, and even if you successfully removed the culprit, keep in mind that the same app or script might have harvested your login credentials and sent them to the <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/threat-actor\/\" target=\"_blank\" rel=\"noopener\">threat actors<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-19536 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/2falogo.jpg\" alt=\"2fa logo\" width=\"300\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/2falogo.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/2falogo-150x150.jpg 150w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<h3>Summary<\/h3>\n<p>What to do when you find posts in your name on Facebook which you did not post:<\/p>\n<ol>\n<li>Try to find out if there is a suspicious or unsolicited Facebook app active on your list that has posting authorization.<\/li>\n<li>Clear the cache of the browser that you use to access Facebook and the shortcuts you use to open Facebook.<\/li>\n<li>Change your password and consider enabling 2FA.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h3>Other articles that might interest you:<\/h3>\n<ul>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/101\/2016\/06\/facebook-and-privacy\/\" target=\"_blank\" rel=\"noopener\">Facebook and privacy<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/101\/2017\/01\/understanding-the-basics-of-two-factor-authentication\/\" target=\"_blank\" rel=\"noopener\">Understanding the basics of two-factor authentication<\/a><\/li>\n<li><a href=\"https:\/\/www.techworm.net\/2017\/08\/facebook-messenger-scam-targeting-victims-via-video-link-malware.html\" target=\"_blank\" rel=\"noopener\">Facebook Messenger Spam Spreading Malicious Chrome Extensions<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em>Pieter Arntz<\/em><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/101\/fyi\/2017\/09\/facebook-worries-i-didnt-post-that\/\">Facebook worries: I didn\u2019t post that<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/101\/fyi\/2017\/09\/facebook-worries-i-didnt-post-that\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Wed, 06 Sep 2017 15:00:12 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/101\/fyi\/2017\/09\/facebook-worries-i-didnt-post-that\/' title='Facebook worries: I didn\u2019t post that'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/shutterstock_401648989.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>What could have happened when you find Facebook posts or messages that you didn&#8217;t post or send? And what are the actions you can take to prevent further abuse?<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/101\/\" rel=\"category tag\">101<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/101\/fyi\/\" rel=\"category tag\">FYI<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/apps\/\" rel=\"tag\">apps<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/facebook\/\" rel=\"tag\">facebook<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/facebook-messenger\/\" rel=\"tag\">Facebook Messenger<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/permissions\/\" rel=\"tag\">permissions<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/pieter-arntz\/\" rel=\"tag\">Pieter Arntz<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/the-more-you-know\/\" rel=\"tag\">the more you know<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/101\/fyi\/2017\/09\/facebook-worries-i-didnt-post-that\/' title='Facebook worries: I didn\u2019t post that'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/101\/fyi\/2017\/09\/facebook-worries-i-didnt-post-that\/\">Facebook worries: I didn\u2019t post that<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10519,8816,3589,14359,10520,12507,10523,10524],"class_list":["post-9112","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-10519","tag-apps","tag-facebook","tag-facebook-messenger","tag-fyi","tag-permissions","tag-pieter-arntz","tag-the-more-you-know"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9112","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=9112"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9112\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=9112"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=9112"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=9112"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}