Latest Comments
"I too have been a labor voter for many years and will not be voting for them again. The ..."
by maxt | Feb 9, 2010 7:56 PM
 
"I’ve just had a user receive a rehashed version of this with an attached html file containing a ..."
by Owen Lutz | Feb 9, 2010 6:01 PM
 
"hi"
by manish kumar | Feb 9, 2010 4:27 PM
 
"Hey 'hey con-roy' ... from Google Australia's head of policy Iarla Flynn"We don't believe that ..."
by Keep it real | Feb 9, 2010 3:33 PM
 
"@penno Off-site storage is a good solution unless you have some decent backup software to ..."
by Charmgene | Feb 9, 2010 2:36 PM

Twitter accounts compromised in torrent site scam

  • Email a Friend
  • Print Page
Twitter accounts compromised in torrent site scam
By Angela Moscaritolo
Feb 4, 2010 11:53 AM | 1 Comment
Tags: Twitter | accounts | compromised | torrent | site | scam | social | networking | web
Poor password management to blame.

Twitter this week reset the passwords of some of its users after discovering malicious file-sharing sites that were set up to steal users' login credentials.

During regular monitoring of its user base for suspicious activity, Twitter noticed a sudden surge in followers for several accounts within the last five days, Del Harvey, Twitter's director of trust and safety, wrote in a blog post. After investigating the issue, Twitter discovered that some of the accounts following the suspicious users were compromised by an attacker who stole login credentials from rogue file-sharing “torrent” sites.

For several years, an individual had been setting up torrent sites, as well as forums for torrent site usage, Harvey said. This individual sold these supposedly well-crafted sites and forums to others who wanted to start their own torrent download sites.

What buyers didn't know is that the sites and forums were actually riddled with security exploits and backdoors, which allowed the cybercriminal to gain access to the sites and steal users' login details.

“This person then waited for the forums and sites to get popular and then used those exploits to get access to the username, email address and password of every person who had signed up,” Harvey wrote.

The cybercriminal was able to use the stolen login information to gain access to third-party sites, such as Twitter, because many individuals used the same password for multiple sites.

“The takeaway from this is that people are continuing to use the same email address and password (or a variant) on multiple sites,” Harvey wrote. “Through our discussions with affected users, we've discovered a high correlation between folks who have used third-party forums and download sites and folks who were on our list of possibly affected accounts.”

Twitter reset the passwords for all accounts that were following the suspicious users, Harvey said. Twitter did not say how many accounts were affected.

This is the first time Twitter has identified this particular attack vector, he added.

The incident should be a warning for users not to use the same password for multiple sites, Jamie Tomasello, abuse operations manager at messaging security firm Cloudmark, told SCMagazineUS.com.

Whoever was behind this attack now can also attempt to gain access to user accounts on other sites besides Twitter, Tomasello added.

“I would not be surprised if they were using these same passwords against other social networking sites, banking sites and e-commerce sites,” she said.  

Meanwhile, Randy Abrams, director of technical education at anti-virus vendor ESET, commended Twitter for resetting users' passwords.   

“It really would be prudent for all of the social networking sites to start enforcing a mandatory password change at least once a year, if not more frequently, but that holds true for banks and other financial institutions as well,” Abrams told SCMagazineUS.com.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 1
Not to mention, it's bad practice to use and/or necessitate the use of an email address as a username.
SC Magazine - comments icon Posted by bad practiceFeb 5, 2010 9:55 AM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Vulnerabilities & Exploits Whitepapers