Skip to navigation
   
Asavin Wattanajantra's Blog

Twitter hit by ANOTHER attack - but this ain’t no worm

By Asavin Wattanajantra in Editorial

Posted in worm, social engineering, phishing, Twitter, Security on June 2, 2009 at 3:16 pm

Permalink | Author Profile

If you’ve followed IT PRO for any length of time, you’ll probably know that Twitter has been suffering security wise all year.

The latest attack that became public on the weekend was first believed to be a cross-scripting worm, similar to the worm that a 17-year old managed to unleash on the Easter weekend.

However on closer inspection this isn’t all there is to it, according a post on Kapsersky’s Viruslist blog.

When clicking the link to tweets reading ‘best video’, a connection is quietly made to another server resulting in a malicious PDF being downloaded, which contains several exploits.

However, instead of a worm being downloaded with a successful exploit, a fake program will be downloaded, advertising fake anti-virus software.

The researcher couldn’t find any worm-like component, although the alert made it look like there was worm activity.

An explanation for this could simply be that the criminals behind the attack were using the stolen credentials of accounts which had been phished a week ago.

The blog said : “The attack is very significant. It would seem that at least one criminal group is now exploring the distribution of for-profit on Twitter.

“If the trends we’ve seen on other social platforms are any indicator for Twitter then we can only expect an increase in attacks.”

Twitter seems to be regularly hit with some sort of security scare, ever since January when a teenage hacker managed to take over high-profile accounts, while even celebrity twitterer Stephen Fry fell victim to a phishing attack.

We’ve also seen how a security researcher has said that Twitter’s API, used to make third party applications, is inherently flawed.

IT PRO has constantly tried to get in touch with Twitter simply to have some kind of statement, but has so far just come across a brick wall.

So what’s Biz and co gonna do? You can’t make money on something which is inherently unsafe (or can you?).

12345
Not yet rated
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Trackback by Rufus Azcona - February 9, 2012 on 7:49 am

will smith divorce…

[…]practice in the place of game[…]…

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

Hitwise Sophos Steve Jobs staff illegal brain broadband virtual worlds old school university of portsmouth alcohol worm Farmville Facebook Klingon video James Bond pod casting Twitpocalypse iPhone funny legal Pirate Bay DNSSEC tool BERTI sightings Twitter Fraud news Bill Gates poking Firefox Digital Britain MMORPG hack trend micro Sega ducks status eBooks malware mobile Wherecloud Republicans Kaminsky crime Digg Beijing IM Sonic FBI opinion Clampi rickrolling Second Life Mario hatred feed robots app flaw Amazon World of Warcraft Daily Mail RSS government flashmob satnav multimedia Spotify sony playstation Nintendo Sega Sinclair Spectrum gaming Mario Sonic paranoia Apple website internet data breaches Mozilla instant messaging Microsoft death Terminator IT PRO phone Cisco password browser science Transformers alibi teenagers credit card data spam unlimited filters Mafia Wars Friendfeed uSwitch hackers remote working brainwaves surveillance tech hacking Google Maps morph growth ID cards Christmas downloading research top ten tips PR swear words pirate bendy crime map Google software YouTube Google Reader RPG lapto smartphone Google hype murder Flurry replies Dark Market nokia update Black Hat SQL injection future offline NHS pride traffic social media military David Blunkett music cybercrime privacy DNS Kindle Star Trek human clones Google Street View flexible working Scrabble control kill fire BlackBerry ASA fun streaming Nintendo vote medials journalism ENISA Olympics video games Lewis hamilton phishing cyber crime
Advertisement
Advertisement