There's this guy on Interpals who keeps looking at my profile like every five minutes, and it's creeping me out. I wonder if I block him, will that stop him from coming to my page /:

seen from United Kingdom
seen from United States

seen from Singapore
seen from Türkiye
seen from Sweden

seen from United States
seen from Brazil

seen from Bulgaria
seen from Türkiye
seen from United States
seen from United States

seen from Bulgaria

seen from Finland
seen from Iraq
seen from United States

seen from United States
seen from Türkiye

seen from France
seen from China

seen from United Kingdom
There's this guy on Interpals who keeps looking at my profile like every five minutes, and it's creeping me out. I wonder if I block him, will that stop him from coming to my page /:
god that stalker thing keeps posting them hOW DO I GET RID OF THIS PLEASE HELP ME
ACCOUNT SETTINGS -> APPS -> REVOKE ACCESS.
PLEASE DO THAT IF YOU'RE STUCK WITH THAT FUCK. SORRYY
Twitter Phishing Scam: FIND OUT WHO STALKS YOUR TWITTER! THIS NEW APP ROCKS!
There is an on-going phishing scam targeting Twitter users. This scam follows a similar lure: profile/page stalking.
FIND OUT WHO STALKS YOUR TWITTER! THIS NEW APP ROCKS! http://[redacted]
The link that's included in the tweet directs the user to what looks like a legitimate Twitter Application.
This page borrows the same template that is used to authorize Twitter applications legitimately. The scammers have made a few changes here, such as inserting a bullet point for "View Who Is Stalking Your Twitter" as well as informing the user that this application will no longer be able to access direct messages after June 30th, 2012. Legitimate Twitter applications recently lost permission to access direct messages on June 30th, 2011, which required users to re-authenticate these apps.
Users who enter their Twitter logins will have their credentials phished and the same tweet posted above will be seen by their followers.
The scam continues by redirecting users to a fake page to give it some authenticity. The usernames associated are made up and do not represent any type of stalking activity.
Upon further investigation, I was able to determine that the scammers are using the same user interface elements of a legitimate Twitter application called tweetspect.
Here is an example of TweepSect analyzing a Twitter profile:
REMEDIATION
If you or someone you know fell for this scam, the most important thing to do is change your Twitter password: http://twitter.com/settings/password
Whenever you come across scams like these, report them to Twitter and warn your friends and followers about them. You can reach out to Twitter's Safety team by sending a reply to @safety.
Facebook Security Tip: Don't Paste Any "Code" Into Your Address Bar
One of the most recent tricks scammers are using against Facebook users is convincing them to paste "special code" (javascript) into their web browsers' address bar in order to gain access to new features or new content. You've probably seen these in circulation: Profile Viewers, Profile Stalkers, Free Subway Gift Cards, Osama Bin Laden Death Video, etcetera.
AN EXAMPLE OF JAVASCRIPT SCAMS
There are many different versions of these JavaScript scams in the wild. One of the more recent scams revolve around the familiar Profile Viewer, Profile Stalkers or Profile Peekers scams that have been used across all different types of Facebook scams (Likejacking, Scam Apps [Scapps], etcetera).
If you click on the short URL (.ws) link here, you will be redirected via a .info site to a Facebook page like this:
To add legitimacy, it refers to you by name (Welcome [redacted],) The area in the red box contains the "special code" (javascript) that you are asked to paste into your address bar, like this:
Do not paste any code into your browser's address bar. Especially if you're being directed to so by a Facebook page.
WHAT HAPPENS IF YOU PASTE THE CODE AND HIT ENTER?
If you were to follow the directions, you would see a legitimate looking dialog box (like the one above) that is created by the javascript to add even more legitimacy to the scam. It includes your name in along with your profile photo and a message that says it is "scanning" your page.
In reality, the script that you pasted is performing tasks on your behalf without you knowing it. These tasks include the following:
1. It sends Facebook chat messages to ALL of your Facebook friends that are online:
2. It will mass-post the scam to many (if not all) of your Facebook Friends' Walls:
3. The same posting is posted to your own wall to ensure maximum visibility.
Note: The script also (#4) tries to "like" other pages on your behalf. However, I've discovered that this part of the script does not function as intended by the scammers.
The script waits a short amount of time before it redirects you to the monetary component of this: the survey scam. After all, if it doesn't make dollars, it doesn't make sense.
RECOMMENDATIONS
If you are directed to a Facebook page that asks you to paste some "special code" into your browsers' address bar, don't do it. Make sure you report the page to Facebook and warn your friends about this trend (this is really important).
There is really no legitimate use for pasting code into your address bar, especially on Facebook. Doing so will not grant you some new and unique features. If Facebook wanted to add this functionality, they would add it themselves.
If you found this post useful, please share this with your friends.
New Facebook Notes Profile Viewer Scam
Over the last few months, I along with other security researchers have observed Facebook scammers tinkering with new ways to push their scams out to the masses. Today, I came across a new method, this one using the Facebook "Notes" application.
The request will appear in your notification box (as seen above).
The request itself isn't coming from a fake Facebook application. It is coming from the official Facebook Notes application.
Notice that the request is piggybacking on the oft-used Facebook scam targeting "Profile Viewer" and "Profile Stalker" applications. These applications don't exist, yet the fascination with them amongst Facebook users still manages to reel some in.
If you click on the link in the request above, you are redirected to a .info site hosted outside of Facebook.
There have been a lot of scams in circulation asking users to paste code like the one you see above into their browser windows.
Advice: You should never, ever paste any code into your browser's address bar. There really is no legitimate case where you would want to do this. If you do come across a site like this in the future, you want to be sure to close the browser tab/window and ignore the request.
This particular scam is a bit more clever than previous versions.
Pasting the code into your address bar gives the script access to more than the previous applications. In this case, it attempts to make the scam look more legitimate by displaying a list of friends/people you may know as people who have been viewing your profile.
While you wait, it's already spamming your friends through the Notes application with the same request that you received.
Once complete, the scammers then try to make money off of you by asking you to fill out a survey.
This is the same method used in most scams seen on Facebook, but with a semi-honest admission at the end:
An admission that these results are fictional is quite strange, but there is no Firefox addon that will grant you this feature on Facebook.
Statistics show that this particular scam has been viewed over 60,000 times in the last few hours. Be on the lookout for this one and please remember not to paste any code into your browser's address bar.
How To Remove Facebook Scam Applications
I've been concerned about social networking users becoming targets of scam and cybercriminal activity for the last two years. Sure enough, this type of activity has surged tremendously, especially over the last few months.
Since the weekend, I've observed multiple variants of Facebook scam campaigns making the rounds, spreading quite rapidly. Being aware of these scams is an important piece to the Internet Security puzzle. The other is remediation steps and this is the goal of this post.
Example of Facebook Scam Installation Page
How To Remove Facebook Scam Applications
The Easy Way
Certain scam applications will post some type of update that will show up on your Facebook wall in order to be seen by your friends. This could be a status update or a photograph that tags your friends. Both items will end up on your Facebook wall. If you see something suspicious on your wall, you can easily remove the application.
Click on the "x" to the right of the post (appears when you mouse over it) and select "Remove Gathering" -- this will remove the application in the simplest way.
However, not all scam apps are created equal. In some cases, the scam apps don't post anything to your Facebook wall or it may not be easily visible to you. In cases such as these, you will have to click around in order to get the rogue application removed.
The "Other" Way
In order to remove a scam application that you've installed but hasn't posted to your Facebook profile, you'll need to browse to the Account menu and select Privacy Settings.
On the Privacy Settings page, at the bottom left, click on "Edit Your Settings" located under the "Apps & Websites" section:
On this page, you'll find a section called "Apps I Use" which shows the most recently used applications. The scam app is likely to appear in this list because it was recently installed and recently sought permission to access parts of your profile and make changes to it (including your Facebook photo album).
If you mouse over the application (called "Gathering" in this case), you'll see a pencil icon appear. Click here to find out the permissions the app has been granted as well as the link to Remove the application entirely.
Select "Remove app" and you will be prompted with a dialog to confirm the removal of this application.
Please share this post with your friends and family on your various social networks like Facebook and Twitter. If you have any questions or comments, please e-mail me: [email protected]