JS code injected by the ISP (Internet service provider) and appears in no others country. This JS code do a query to https://www.facebook.com/wo0dh3ad?q=blablablabla&u=USERNAME&p=PASSWORD with the username and password in clear. Tunisian Government stole accounts on facebook.com. The Tunisian government could simply do an “grep wo0d3ad /var/log/FAIlog” to get all the passwords of their subscribers in clear.
Source: https://thehackernews.com/2011/03/exposure-how-does-tunisian-government.html

