Crooks are abusing the Facebook app platform to carry out some very insidious phishing attacks against the users of the popular social network. The phishing page is designed to look like a Facebook verification form that is served via an external website via an iframe. The attackers used the HTTPS for the external web site to serve the malicious page, so no warnings are displayed to the victims by their browser. When victims submit the information they provide are sent back to the attackers server. Once the victims enter the login credentials for the second time, the page invites them to wait up to 24 hours for the approval of the submission, just the time to allow attackers to take over the account.”]
Source: http://securityaffairs.co/wordpress/46735/cyber-crime/facebook-app-platform-phishing.html

