Facebook Crush app reveals spyware but no lovers

By Liam Tung on 07 January 2008

Tags: application | facebook | iframe | secret crush | security | social networking | install | claim

Security firm Fortinet has warned that Facebook users face certain disappointment and possible spyware if they attempt to discover who sent them a "Secret Crush" application invite.

Recipients of the Secret Crush invitation are lured to install the application by the promise of finding the so-called sender's identity, which the application hints it will only divulge once the recipient accepts the terms and conditions -- giving the developer access to personal information -- and then invites five friends to install the application as well.

After following the procedures, rather than discovering the identity of the sender, the recipient merely installs a horoscope-based "Crush Calculator" application, which delivers advice on the compatibility of different users that have installed the application.

However, Fortinet's claims of improper behaviour centre on the alleged surreptitiously-installed spyware that is packaged with the application by adware company, Zango.

Want to know more?

For all the latest news, analysis and opinion on security, click here

In November, 2006 Zango, formerly 180solutions, was forced to cede an amount of US$3 million in what the US Federal Trade Commission labelled "ill-gotten gains". Recently, Zango lost its lawsuit against antivirus vendor Kaspersky, after it claimed Zango was a threat to users.

However Zango denies Fortinet's claims, saying it is a victim of circumstance since its iFrame ad became associated with the Secret Crush application due to a third-party advertising partner, which set Zango's ad to appear on Facebook when a user installs the "Secret Crush" application -- a practice Zango claims is "completely legitimate".

"At no point in adding the Secret Crush widget to a Facebook profile does the widget install either spyware or Zango software, or even attempt to do so. Any suggestion that Zango software is being 'secretly installed' is simply not true," Zango claimed on its blog.

"Moreover, our general security monitoring of the Zango network has shown no abnormal increase in installations -- something we would have seen based on the reported usage numbers of the Secret Crush widget," it added. Following initial warnings of the application, Secret Crush was renamed to My Admirer and subsequently disabled.

Fortinet estimates that around three percent of Facebook users currently have the Secret Crush widget installed.

CNET News.com's Robert Vamosi contributed to this report

Like this article? Click below to send it to your mobile for free!

Be the first to comment on this article!

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • Hacker talks fooling e-passport systems

  • Best free Windows Mobile software

  • Trend Micro PC-cillin Internet Security 2009

  • Norton Internet Security 2009: Photos

  • Trend Micro Internet Security 2009 Pro: Photos

  • 101 software tips, tweaks and tricks

  • Don't buy stand-alone antivirus: Trend Micro

  • Norton Internet Security 2009

  • Spyware Terminator

More articles »

Find the right software

Brand
  • Multiple options can be selected

    • Trend Micro PC-cillin Internet Security 2009

      Trend Micro PC-cillin Internet Security 2009

      You can't beat the price. For a good, basic internet security suite, we recommend Trend Micro Internet Security 2009.

    • Norton Internet Security 2009

      Norton Internet Security 2009

      Norton Internet Security 2009 hits all the right security notes and its superior protection technologies might even win back some jaded anti-Symantec folks, though the lack of adequate technical support may continue to frustrate.

    • Spyware Terminator

      Spyware Terminator

      This spyware scanner and removal tool does the job, but enabling some functions may cause slight slowdowns and it has a few bugs in Vista.

    • ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security Suite 2009

      ZoneAlarm Internet Security 2009 provides top-notch security protection that is light on system resources, allowing you to work unencumbered.

    • Ad-Aware 2008

      Ad-Aware 2008

      This year's update to user favourite Ad-Aware is quite a significant overhaul, and the result is faster scan times and a new interface.

    More reviews »

    Membership benefits

    Create a personalised homepage

    Create a personalised homepage

    Choose your interests from our 16 categories and only see articles relevant to you. Sign up for a free CNET.com.au membership now!