
This Cheerleaders Gone Wild clickjacking attack hid behind a fake content warning.
(Credit:
Sophos)
Another warning then popped up pretending to be an antispam mechanism that asked the user to click three buttons numbered 1, 2, and 3 in a specific order. Once that was done and the "submit" button was clicked, the user's account then submitted that it "likes" the Cheerleaders Gone Wild page and that message was broadcast from the victim's account to his or her newsfeed for all friends to see, Cluley said.
Read more: http://news.cnet.com/security/?tag=hdr;snav#ixzz0z89WUNUS