Twitter Halts Vulgar Malware Attack
Offensive tweets about goats hijacked user accounts using cross-site request forgery.
![]() | |
Slideshow: Top 10 Tech Newsmakers Of 2010 | |
| (click for larger image and for full photo gallery) |
The tweet in question turned out to be an attack that "spread vulgar messages [about goats] from many affected users' accounts" -- said Graham Cluley, senior technology consultant at Sophos.
More Storage Insights
Webcasts
- Best Practices in SMB Desktop Virtualization
- Forrester Total Economic Impact study of Midrange Storage
White Papers
- Silver Peaks Advantages in a Disaster Recovery Environment
- Dissolving Distance: Silver Peaks Technology Overview
Reports
More >>That message was followed by "WTF" and a link. "Clicking on the WTF link would take you to a webpage which contained some trivial code which used a CSRF -- cross-site request forgery -- technique to automatically post from the visitor's Twitter account," he said.
Twitter users, however, would be none the wiser that they'd just stumbled into a CSRF attack, since after clicking the link all they saw was a blank screen. Meanwhile, the attack had already used the user's Twitter account to post more goat-related messages with malicious links.
"Some high-profile Twitter users, including Robert Scoble, fell foul of the attack," said Cluley. "Of course, having such popular Twitter users affected accelerated the spread of the message."
This attack follows a recent and arguably more dangerous attack that used a cross-site scripting vulnerability to craft a malicious link. All a user had to do was to move his or her mouse pointer over the link, and the malicious code could open pop-up windows or third-party websites.
For the goat-related attack, by late Sunday, Twitter said that it had "fixed the exploit" by disabling the links and was "in the process of removing the offending Tweets."
But Cluley said the underlying CSRF holes are "an obvious security problem in Twitter which must be addressed as a matter of urgency -- otherwise we can expect further, perhaps more dangerous, attacks."
Continuous data protection used to be a pipe dream for most outside the financial world because of sky-high cost and complexity. That's changing, creating new options for businesses that require different thinking about disaster recovery. Download our report here (registration required).
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Subscribe to RSSResource Links
Related Webcasts
- Reduce Cost and Improve Manageability with IBM Windows Storage Server
- Data Protection and Microsoft Office 365: How Proofpoint Addresses Concerns of the Distributed Enterprise
- Best Practices in SMB Desktop Virtualization
- CTO to CTO: Scott Davies, VMware, and Jim Davies, Mitel, Give Voice to the Virtual Desktop
- Forrester Total Economic Impact study of Midrange Storage
This Week's Issue
Free Print Subscription
SubscribeCurrent Healthcare Issue
- InformationWeek Healthcare CIO 25: Our second annual honor roll of the health IT leaders driving healthcare's transformation.
- EHR Unreadiness: Only a small percentage of physicians planning to apply for Meaningful Use funds have e-health record systems capable of achieving most of the requirements. .
- And much more!
- Read the Current Issue
Related Whitepapers
- Silver Peaks Advantages in a Disaster Recovery Environment
- Dissolving Distance: Silver Peaks Technology Overview
- Five Ways to Optimize Offsite Storage and Business Continuity: A WAN Optimization Primer for Storage Professionals
- Data center operational efficiency best practices
- How to Prepare Your Virtualized Data Center for the Cloud
Featured Resource
"Read this white paper to learn about the security issues you need to consider and how IBM assessment services and guidelines for securing cloud implementations can help you maximize the business value of cloud investments while minimizing risk.
Read Now













