Skip to navigation
   
Asavin Wattanajantra's Blog

Twitter hit by ANOTHER attack - but this ain’t no worm

By Asavin Wattanajantra in Editorial

Posted in worm, social engineering, phishing, Twitter, Security on June 2, 2009 at 3:16 pm

Permalink | Author Profile

If you’ve followed IT PRO for any length of time, you’ll probably know that Twitter has been suffering security wise all year.

The latest attack that became public on the weekend was first believed to be a cross-scripting worm, similar to the worm that a 17-year old managed to unleash on the Easter weekend.

However on closer inspection this isn’t all there is to it, according a post on Kapsersky’s Viruslist blog.

When clicking the link to tweets reading ‘best video’, a connection is quietly made to another server resulting in a malicious PDF being downloaded, which contains several exploits.

However, instead of a worm being downloaded with a successful exploit, a fake program will be downloaded, advertising fake anti-virus software.

The researcher couldn’t find any worm-like component, although the alert made it look like there was worm activity.

An explanation for this could simply be that the criminals behind the attack were using the stolen credentials of accounts which had been phished a week ago.

The blog said : “The attack is very significant. It would seem that at least one criminal group is now exploring the distribution of for-profit on Twitter.

“If the trends we’ve seen on other social platforms are any indicator for Twitter then we can only expect an increase in attacks.”

Twitter seems to be regularly hit with some sort of security scare, ever since January when a teenage hacker managed to take over high-profile accounts, while even celebrity twitterer Stephen Fry fell victim to a phishing attack.

We’ve also seen how a security researcher has said that Twitter’s API, used to make third party applications, is inherently flawed.

IT PRO has constantly tried to get in touch with Twitter simply to have some kind of statement, but has so far just come across a brick wall.

So what’s Biz and co gonna do? You can’t make money on something which is inherently unsafe (or can you?).

12345
Not yet rated
Loading ... Loading ...

 

   
Tag cloud

hatred crime phishing human clones Fraud ducks Firefox worm World of Warcraft Twitpocalypse PR alcohol RPG government hack Mafia Wars Google Maps Friendfeed legal RSS smartphone crime map Google Terminator Kaminsky credit card data brainwaves SQL injection virtual worlds Transformers multimedia ENISA Scrabble social media app iPhone tech hacking David Blunkett Bill Gates Mozilla illegal Sophos Twitter password Spotify alibi data breaches Farmville Cisco spam malware instant messaging Sonic replies Black Hat university of portsmouth control traffic flexible working poking military Star Trek browser filters opinion Beijing Hitwise research tool music Facebook DNSSEC Flurry Steve Jobs IT PRO paranoia downloading NHS lapto phone kill Pirate Bay old school privacy rickrolling Digg brain remote working Nintendo Microsoft Apple flaw BERTI journalism uSwitch trend micro funny ASA fire swear words pirate Second Life teenagers bendy sightings fun pod casting robots Sega FBI Digital Britain flashmob Kindle ID cards murder future hackers MMORPG Google Street View IM feed medials status update Google satnav hype eBooks science James Bond video Christmas Olympics Amazon software Clampi YouTube Dark Market surveillance staff cyber crime death morph website streaming mobile Klingon sony playstation Nintendo Sega Sinclair Spectrum gaming Mario Sonic internet nokia BlackBerry Wherecloud offline vote Republicans Daily Mail cybercrime DNS growth unlimited news Mario pride Lewis hamilton broadband Google Reader top ten tips video games
Advertisement
Advertisement