Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

May 22nd, 2009, 08:02 GMT · By

Twitterers, Stay Clear of Tvviter

SHARE:

Adjust text size:


Twitter users targeted by phishers
Enlarge picture
A new phishing campaign has hit microblogging service Twitter, security researchers warn. Users are spammed with a short URL pointing to tvviter.com, where a fake Twitter login page attempts to trick them into handing over their login credentials.

Just as it is the case with many phishing schemes, this one also preys on the curiosity of people. This is reflected in several aspects of the attack. First, the cybercrooks set up fake, randomly named accounts, such as 3XNJTVJG0SYIKDH. They then post a single update of the form: "check this guy out [TinyURL]."

The account is then used to start following other users, who will be notified by Twitter via e-mail about their new follower. The strange name alone might be enough to entice people into checking it out and seeing the bait message. Furthermore, clicking on the shortened URL will open a link to tvviter.com, where they will be served with a Twitter-like login page.

This has the purpose of tricking users into believing that, for some reason, their session has expired and they need to re-authenticate in order to continue to the actual destination page. The domain name itself has been particularly chosen to keep potential victims unwary of the attack.

"Further analysis suggests that there are many other bogus Twitter users out there telling you to 'check this out' and pointing to the same TinyURL link this morning," Graham Cluley, senior technology consultant at Sophos, warns. He also advises that falling for this trick "could lead ultimately to some painful identity fraud, as well as your account being used for the purposes of spam or spreading malware)."

The popularity boom registered by Twitter during the past year has also attracted a lot of cybercriminals, who are trying to profit from the heavy traffic and massive user base. Beginning with this year in particular, the website's administration has had to deal with a constant stream of security incidents, ranging from phishing and spam campaigns, to clickjacking and account hijacking through brute force and social engineering.

A bunch of serious cross-site scripting weaknesses has also been found on the website. Last month, the Twitter staff were forced to play a cat-and-mouse game with a hacker calling himself Mikeyy, who released at least four XSS-based worms on the network during the course of a single week.

TELL US WHAT YOU THINK:

1,658 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


The New York Times Twitter Account Hijacked

Real-Time E-mail Harvesting on Twitter

Twitter Admin Account Hacked via Social Engineering

Mikeyy's Worms Hit Twitter for the Fourth Time

Twitter Hit Three Times by Worms During the Weekend

READER COMMENTS:


Comment #1 by: Gerri on 22 May 2009, 17:59 UTC reply to this comment

It appears that the site has now been blocked: good deal. It would, however, be nice if twitter followed Facebook's lead and implemented Extended Validation SSL already -- the difference between "twitter" and "tvviter" would be easier to spot if the url changed color, too. And even more unsettling is what people can gain from hijacking a twitter or facebook account these days...there was a pretty amusing story on I believe techcrunch about a facebook hijacker that tried to get a "friend" to wire him money until false pretenses.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM