Apr 13, 2009 03:05 PM in Technology | 3 comments
Hacker targets Twitter to teach the company a lesson in security
When computer programmers find security flaws in the programs they use (particularly software running on the Web), they have a choice: report the glitch to the software maker (which may ignore the warning) or find some way of publicly (and often illegally) exploiting it to make clear to the company how vulnerable its software is. A 17-year-old hacker claiming to be from Brooklyn, N.Y., this past weekend chose the latter path, unleashing at least two worms after discovering a weak spot in the social network site Twitter; the worms wended their way into a reported 190 user accounts and infected about 10,000 tweets (messages sent via the Twitter network), the company said yesterday.
A teen identifying himself as Michael “Mikeyy” Mooney has claimed credit for the cyber attacks, Net News Daily reports. (The site even posted a transcript of an interview reportedly conducted via a chat with Mooney shortly after the strikes began.) The first worm sent tweets to Twitter users inviting them to join the StalkDaily.com Web site. When tweeters visit the site, their computers become infected and automatically send out tweets enticing others to visit the site. (Warning: Do not visit this website, because it may trigger an infection in your computer, according to American News World).
A second worm sent out the messages: "Twitter please fix this, regards Mikeyy" and "Mikeyy is done." Mooney told Net News Daily that he had identified a security loophole in Twitter's site about a week ago and decided to "fiddle" with it out of "boredom." Mooney acknowledged that he could go to jail for his actions, but insisted his only intent was to alert Twitter to a programming flaw. (He doesn't mention whether he ever tried to flag the problem simply by contacting Twitter.)
Twitter said on its blog that it's still investigating what happened and how but that "no passwords, phone numbers, or other sensitive information was compromised" during three separate attacks on Saturday and Sunday. During interviews with Brooklyn-based BNO NEWS and Net News Daily, Mooney said he had no intention to rip off Twitter users' personal info.
Online watchdog Watshit offers the following advice for tweeters eager to protect their accounts: Do not use the same password for your Twitter account and e-mail; that way, your e-mail will be protected if your Twitter account is compromised (and vice versa).
Image ©iStockphoto.com/ Sami Suni
You Might Also Like
Discuss This Article
Subscription Center
Most Popular Blog Posts
9,000-year-old brew hitting the shelves this summer
New solar-cell efficiency record set
AIDS vaccine surprises scientists, proves partially successful
Is birth control the answer to environmental ills?
Editor's Pick
-
Adapting to the Freshwater CrisisForward-thinking experts are getting a better handle on the growing global water shortage and coming up with innovative approaches to ensuring the security, safety and sustainability of this resource
Technology Newsletter
Get weekly coverage delivered to your inboxPodcasts
-
60-Second Earth
RSS ·
iTunes
The Jellyfish Menace
click to enable
-
60-Second Science
RSS ·
iTunes
Plants Share Light If Neighbor Is Related
click to enable
Slideshows
Illuminating the Lilliputian: 10 Bioscapes Photo Contest Winners Revealed
Will solar thermal heat up again?
Embarrassing security leaks prompt bill to clamp down on government P2P use
Fight to protect California condors from lead ammunition moves to Arizona
Circulation of LHC Beams Could Resume in Earnest over the Weekend
Measuring Up: New NIST Director, Plus Big Budget Put Measurement Science in Public Eye
How Long Can a Nuclear Reactor Last?
What to Do About Endocrine Disruptors? A Q&A with Linda Birnbaum



