Twitter accounts compromised in torrent site scam
From SC Magazine | 2010-02-04 11:05:09
<div id="subtitle">Twitter this week reset the passwords on an unknown number of accounts after discovering malicious file-sharing sites were set up to steal user login information.</div><div><p>Twitter this week reset the passwords of some of its users after discovering malicious file-sharing sites that were set up to steal users' login credentials. During regular monitoring of its user base for suspicious activity, Twitter noticed a sudden surge in followers for several accounts within the last five days, Del Harvey, Twitter's director of trust and safety, wrote in a blog post Tuesday. After investigating the issue, Twitter discovered that some of the accounts following the suspicious users were compromised by an attacker who stole login credentials from rogue file-sharing “torrent” sites.For several years, an individual had been setting up torrent sites, as well as forums for torrent site usage, Harvey said. This individual sold these supposedly well-crafted sites and forums to others who wanted to start their own torrent download sites. What buyers didn't know is that the sites and forums were actually riddled with security exploits and backdoors, which allowed the cybercriminal to gain access to the sites and steal users' login details. “This person then waited for the forums and sites to get popular and then used those exploits to get access to the username, email address and password of every person who had signed up,” Harvey wrote. The cybercriminal was able to use the stolen login information to gain access to third-party sites, such as Twitter, because many individuals used the same password for multiple sites.“The takeaway from this is that people are continuing to use the same email address and password (or a variant) on multiple sites,” Harvey wrote. “Through our discussions with affected users, we've discovered a high correlation between folks who have used third-party forums and download sites and folks who were on our list of possibly affected accounts.”Twitter reset the passwords for all accounts that were following the suspicious users, Harvey said. Twitter did not say how many accounts were affected.This is the first time Twitter has identified this particular attack vector, he added. The incident should be a warning for users not to use the same password for multiple sites, Jamie Tomasello, abuse operations manager at messaging security firm Cloudmark, told SCMagazineUS.com on Wednesday. Whoever was behind this attack now can also attempt to gain access to user accounts on other sites besides Twitter, Tomasello added. “I would not be surprised if they were using these same passwords against other social networking sites, banking sites and e-commerce sites,” she said. Meanwhile, Randy Abrams, director of technical education at anti-virus vendor ESET, commended Twitter for resetting users' passwords.
“It really would be prudent for all of the social networking sites to start enforcing a mandatory password change at least once a year, if not more frequently, but that holds true for banks and other financial institutions as well,” Abrams told SCMagazineUS.com on Wednesday. </p><img src="http://admatch-syndication.mochila.com/images/ad.gif?aid=68434810&bid=informcom" /></div><div id="copyright"><div>
“It really would be prudent for all of the social networking sites to start enforcing a mandatory password change at least once a year, if not more frequently, but that holds true for banks and other financial institutions as well,” Abrams told SCMagazineUS.com on Wednesday. </p><img src="http://admatch-syndication.mochila.com/images/ad.gif?aid=68434810&bid=informcom" /></div><div id="copyright"><div>
Copyright 2010 <a href="http://content.mochila.com/api/content/asset?assetID=2010-02-04:HaymarketMediaGroup/SCMagazines/Twitter_accounts_compromised_in_-76618/&uname=mochila_api&cert=d1ff44fd2ac969664ae05bf7687cc5d1&bpid=informcom">SC Magazine</a></div></div>
Related Video by 5min
Related Articles
- BMW Plans Production of New Concept Car SmartMoney | 2010-03-18 07:36:07
- Mazda: Focus on eco-friendly and fun speed demons Victoria Times-Colonist, Canada | 2010-03-19 12:21:56
- Haunting beauty The Times, South Africa | 2010-03-13 17:57:31
- Sporty 'prius' Bangkok Post, Thailand | 2010-03-19 17:23:01
- Petty’s Garage Creates Limited-Edition Signat... Automobile | 2010-03-18 16:06:38
- Fort Lauderdale Auto Show Rolls Into Town ABC 10 Miami (WPLG) | 2010-03-18 04:06:19
Related Blogs
- Citroen teams up with British GQ for a Special Concept Car Luxist | 2010-03-16 03:44:00
- Edmunds Roundup: March 16, 2010 Edmunds' Strategies for Smart Car Buyers | 2010-03-16 16:25:32
- Hemmings Find of the Day – 1993 Chrysler 300C Hemmings Auto Blogs | 2010-03-19 13:40:46
- Bugatti 16C Galibier Spreads Its Doors Open Wide [Concept Cars] Jalopnik | 2010-03-16 14:20:16
- Bugatti Shows the 16C Galibier in Black Luxist | 2010-03-16 21:21:05