Wednesday, 24 October 2012

Oh my god, I’ve been hacked

Your social media account is suddenly spamming people like crazy, all your friends are badgering you, sending you lots of messages that you’ve been hacked!
Well often as not you haven’t, you’ve been click-jacked. A link that someone sent you took you to a page with an exploit that is now using your account to get more people to go to the page with the exploit, and so on, ad infinitum. It doesn’t really matter how they got you though, in most cases doing the following will sort it out:

  1. Change your password:
    1. Pick something strong, correct horse battery staple or get a password manager and use long random strings full of symbols as well as letters and numbers.
    2. If your account has actually been broken into you may need to use the “Forgotten password” functionality, it will be a link under the password box on the login form.
    3. You can change your password here on twitter and on this facebook page.



  2. Check your authorised apps list:
    1. Look at everything that has permission to use your account and revoke any you don’t recognise/use any more, worst case is if you revoke something you do use you’ll need to authorise it again.
    2. Twitter now prompts you to do this after password change, but you can also go find the list yourself and again here is the page for facebook.



  3. BE MORE CAREFUL WHAT YOU DO ON THE INTERNET. IT IS A JUNGLE OUT THERE.
These examples are for twitter and facebook, but the same concepts apply to other sites.

No comments: