NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Incidents

Incidents


Mikeyy's Worms Hit Twitter for the Fourth Time

The service's staff has trouble keeping up with all the XSS weaknesses

By Lucian Constantin, Web News Editor

14th of April 2009, 10:39 GMT

Adjust text size:


Twitter administration has trouble securing the micro blogging platform from XSS attacks
Enlarge picture
Late on Saturday and Monday, the increasingly popular micro-blogging platform Twitter faced the e-wrath of Mikeyy again. A new worm released by the teenager affected its users, who unwillingly began to post new rogue messages on their profiles.

During this past weekend, the Twitter staff fought a cat-and-mouse game with Mikeyy Mooney, a 17-year-old Web programmer, who discovered several cross-site scripting flaws affecting the service. In an interview for an online publication, Mikeyy admitted to the attacks and attributed them to boredom.

By exploiting the XSS flaws that he identified while inspecting Twitter's source code in order to create his own similar service, the teenager succeeded in launching worm-like attacks. The intriguing code was causing users who were visiting compromised profiles to be infected themselves and propagate the malicious messages.

In total, three waves of attacks were acknowledged by Twitter Co-Founder Biz Stone on the company's blog. The service's staff had to temporarily suspend and reset passwords on hundreds of accounts, as well as clean over 10,000 abusive tweets (messages posted on Twitter).

Each incident was followed by assurances from the management that the exploited cross-site scripting vulnerabilities had been patched. "Every time we battle an attack, we evaluate our web coding practices to learn how we can do better to prevent them in the future," Mr. Stone noted.

This forth wave of attacks mocked Twitter security and the efforts of the admins working around the clock to keep up with them. Some of the messages read, "Twitter, hire Mikeyy!," followed by what some journalists confirmed to be the teenager's real phone number.

Others promoted a short URL, which allegedly had cleaning instructions for the worm. However, it was only meant to further propagate it, because clicking on the link redirected users to a compromised profile, causing theirs to be affected as well.

Twitter confirmed this new attack and pointed out that it had been dealt with, but Graham Cluley, senior technology consultant at anti-virus vendor Sophos, is not so convinced. "What's most alarming to me, though, is that it seems Twitter was caught with its pants down in the aftermath of all of these attacks. To be hit by one cross-site scripting worm may be regarded as a misfortune, to be struck three or four times over a weekend looks like carelessness," the security researcher writes.

TAGS:

Twitter worm | cross-site scripting | XSS weakness | Mikeyy Mooney | rogue tweets
Read by 1,124 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Twitter Hit Three Times by Worms During the Weekend

XSS Flaw Hits Twitter

Hijacked Twitter Accounts Used in Webcam Scheme

More Twitter Clickjacking

Miley Cyrus' Twitter Account Hacked

Twitter Clickjacking Fix Circumvented

Clickjacking Attack Launched on Twitter

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM