Advertisement
Promo

Security threats Toolkit

Twitter fends off weekend worm attacks

Elinor Mills CNET News

Published: 14 Apr 2009 13:11 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Twitter security engineers were cleaning up on Monday following a series of worm attacks over the weekend, including at least two credited to a bored 17-year-old.

In the first attack, which began early on Saturday, four new accounts began spreading a worm, compromising about 90 accounts, Twitter co-founder Biz Stone wrote in a posting on the Twitter blog.

The worms appeared to do no damage other than spread to infected users' followers and modify profile pages. You can become infected just by clicking on the name or image of someone whose account was infected.

Later that afternoon, about 100 accounts were compromised in a second wave, followed by another wave on Sunday morning, Stone wrote. Nearly 10,000 tweets that could have spread the worm were deleted, according to Stone.

Late on Sunday and into Monday morning, Twitter fended off another attack, Stone said. "Once again, we secured the compromised accounts and deleted any material that would further propagate the worm," he wrote. Stone declined an interview request from ZDNet UK's sister site, CNET News.com, saying he did not have time.

The worms exploit a common vulnerability in web applications called cross-site scripting, which allows someone to inject code into web pages others are viewing.

In this instance, Twitter users who clicked on the name or image of anyone sending the worm messages would become infected and then send the message on to all that person's followers. Anyone viewing an infected user's profile would also become infected and pass the worm on.

Interviewed by CNET News.com on Sunday after the first two iterations circulated, Michael Mooney, a 17-year-old living in Brooklyn, said he created the worms out of boredom. The messages in the first outbreak included a link to rival microblogging site, StalkDaily.com, which Mooney owns.

Mooney said in the interview that he did not plan on releasing any more worms targeting Twitter. He could not be reached for comment on Monday.

The first worm messages warned people not to go to the StalkDaily site, which would infect a Twitter user's account if they visited the site. The second worm message contained the word 'Mikeyy', and the third referred to removing the Mikeyy worm, but used 'bit.ly' to add shortened URLs to messages, said Andy Hayter, anti-malcode program manager for ICSA Labs, which provides third-party validation for security products.

Read this

Roundup
Roundup: Countdown to Conficker

ZDNet reports on the latest news and updates

Read more +

The most recent attack involved a message saying 'Hire Mikeyy' and included Mooney's phone number, according to Graham Cluley, a senior technology consultant with security firm Sophos. "What we're seeing was it was possible for codes to be embedded, small pieces of JavaScript, into people's profiles. This should be fairly elemental to filter out," he said.

While the attacks were mostly a nuisance, they could have been dangerous if spyware or other malware had been downloaded onto Twitter users' computers, Cluley said.

To avoid such JavaScript-based attacks, you can turn off JavaScript in your browser. You can also use utilities such as NoScript, an open-source Firefox extension, Hayter recommended.

Users of infected Twitter accounts should also request a password reset and go to the settings page and delete any profile or other information that may have been added during the attack. To reset colours, go to the profile-design page.

Twittercism has detailed instructions on how to tell if you are infected and how to remove the worm.

Just as email users should be careful which email attachments they open, be careful who you follow on Twitter, Hayter warned.

Credit: Twitter cleans up after weekend worm attacks from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters