Kirstie Allsopp among those affected as spammer exploits weaknesses in passwords and in Facebook code to try to tempt people to ‘free’ gadgets A spammer has exploited a serious vulnerability in Facebook’s photo upload system to spam both Facebook and Twitter with photos promising “free” iPads and iPhones. The photos, which were posted to peoples’ walls by exploiting a flaw in which it was not checked whether a photo could be posted to someone’s profile, pretended to be from the profile owner and promoted schemes promising cheap or free gadgets – particularly iPhones and iPads. Among those affected were a friend of Facebook chief executive Mark Zuckerberg – who responded, says the security company Sophos; Zuckerberg responded to the picture by asking his friend “Is this real or did your account get hacked?” Robert McMillan for IDG was the first with the detail, which he says let the spammer post “thousands” of messages on peoples’ Walls.

See original here:
Facebook and Twitter user accounts hacked with ‘free iPad’ scams