Skip to navigation
   
Asavin Wattanajantra's Blog

Twitter hit by ANOTHER attack - but this ain’t no worm

By Asavin Wattanajantra in Editorial

Posted in worm, social engineering, phishing, Twitter, Security on June 2, 2009 at 3:16 pm

Permalink | Author Profile

If you’ve followed IT PRO for any length of time, you’ll probably know that Twitter has been suffering security wise all year.

The latest attack that became public on the weekend was first believed to be a cross-scripting worm, similar to the worm that a 17-year old managed to unleash on the Easter weekend.

However on closer inspection this isn’t all there is to it, according a post on Kapsersky’s Viruslist blog.

When clicking the link to tweets reading ‘best video’, a connection is quietly made to another server resulting in a malicious PDF being downloaded, which contains several exploits.

However, instead of a worm being downloaded with a successful exploit, a fake program will be downloaded, advertising fake anti-virus software.

The researcher couldn’t find any worm-like component, although the alert made it look like there was worm activity.

An explanation for this could simply be that the criminals behind the attack were using the stolen credentials of accounts which had been phished a week ago.

The blog said : “The attack is very significant. It would seem that at least one criminal group is now exploring the distribution of for-profit on Twitter.

“If the trends we’ve seen on other social platforms are any indicator for Twitter then we can only expect an increase in attacks.”

Twitter seems to be regularly hit with some sort of security scare, ever since January when a teenage hacker managed to take over high-profile accounts, while even celebrity twitterer Stephen Fry fell victim to a phishing attack.

We’ve also seen how a security researcher has said that Twitter’s API, used to make third party applications, is inherently flawed.

IT PRO has constantly tried to get in touch with Twitter simply to have some kind of statement, but has so far just come across a brick wall.

So what’s Biz and co gonna do? You can’t make money on something which is inherently unsafe (or can you?).

12345
Not yet rated
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments

Trackback by Rufus Azcona - February 9, 2012 on 7:49 am

will smith divorce…

[…]practice in the place of game[…]…

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

swear words Scrabble trend micro video games flashmob brain FBI BlackBerry sony playstation Nintendo Sega Sinclair Spectrum gaming Mario Sonic brainwaves Star Trek social media hype nokia Farmville Apple software flexible working music robots old school feed data breaches Cisco government David Blunkett credit card data browser teenagers traffic YouTube Black Hat iPhone internet sightings Sega instant messaging Google Street View streaming Firefox Kindle Spotify Digg Sonic phishing lapto medials Amazon control PR kill app remote working Pirate Bay hacking eBooks Klingon ducks Olympics research Friendfeed Twitpocalypse pod casting smartphone murder alcohol Digital Britain virtual worlds IT PRO Microsoft fire pride cyber crime rickrolling future spam World of Warcraft illegal Bill Gates Daily Mail legal top ten tips hatred Transformers ASA password surveillance filters tech hackers James Bond worm alibi Hitwise Google Maps Clampi update Sophos Nintendo broadband DNS pirate flaw mobile Google Reader bendy paranoia growth Twitter crime journalism satnav Fraud Google university of portsmouth opinion ID cards human clones Beijing offline fun Mafia Wars Wherecloud tool Steve Jobs privacy replies status Mozilla Mario MMORPG Facebook unlimited morph crime map Google Republicans RPG Terminator SQL injection downloading BERTI Dark Market Kaminsky poking video science death IM uSwitch military cybercrime RSS Flurry Christmas vote DNSSEC phone website multimedia malware news staff NHS funny Second Life Lewis hamilton hack ENISA
Advertisement
Advertisement