<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; twitter hacked</title>
	<atom:link href="http://www.darknet.org.uk/tag/twitter-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Twitter onMouseOver XSS Exploit Causes Chaos</title>
		<link>http://www.darknet.org.uk/2010/09/twitter-onmouseover-xss-exploit-causes-chaos/</link>
		<comments>http://www.darknet.org.uk/2010/09/twitter-onmouseover-xss-exploit-causes-chaos/#comments</comments>
		<pubDate>Wed, 22 Sep 2010 09:56:07 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[onmouseover]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[twitter exploit]]></category>
		<category><![CDATA[twitter hack]]></category>
		<category><![CDATA[twitter hacked]]></category>
		<category><![CDATA[twitter malware]]></category>
		<category><![CDATA[twitter onmouseover]]></category>
		<category><![CDATA[twitter safety]]></category>
		<category><![CDATA[twitter security]]></category>
		<category><![CDATA[twitter vulnerability]]></category>
		<category><![CDATA[twitter xss]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2955</guid>
		<description><![CDATA[The big news yesterday was an epic XSS flaw on Twitter that sent the micro-blogging service into chaos. They actually made an announcement during the hack that users should stay off the web-site and use 3rd party services through the API (Software such as Tweetdeck, Seesmic, Gravity etc). They posted an update on the status [...]]]></description>
			<content:encoded><![CDATA[<p>The big news yesterday was an epic <a href="http://www.darknet.org.uk/tag/xss/">XSS</a> flaw on <a href="http://www.darknet.org.uk/tag/twitter/">Twitter</a> that sent the micro-blogging service into chaos. They actually made an announcement during the hack that users should stay off the web-site and use 3rd party services through the API (Software such as Tweetdeck, Seesmic, Gravity etc).</p>
<p>They posted an update on the <a href="http://status.twitter.com/post/1161435117/xss-attack-identified-and-patched">status blog</a> pretty fast that the XSS had been identified and they were in the midst of patching it.</p>
<blockquote><p>Hackers have exploited a flaw in Twitter, which results in pop-ups and third-party websites being opened despite users simply hovering over links with their mouse.</p>
<p>Hundred of Twitter users, including Sarah Brown &#8211; wife of the former Labour Prime Minister Gordon Brown &#8211; have fallen victim to the attack. In some cases the third-party websites that are open are pornographic. The malicious links contain Javascript code, called onMouseOver, which allows users to redirected, even if they haven&#8217;t clicked on the link.</p>
<p>Graham Cluely from security firm Sophos said in a blog that at present the flaw is being exploited for &#8220;fun and games&#8221; although &#8220;there is obviously the potential for cybercriminals to redirect users to third-party websites containing malicious code, or for spam advertising pop-ups to be displayed&#8221;.</p>
<p>Cluley advised Twitter users to avoid using the Twitter website and instead rely on a third-party client such as Tweetdeck to access the service. </p></blockquote>
<p>Most &#8216;attacks&#8217; were pretty harmless with users just having fun with the bug, there were some pretty dodgy incidents though involving shocks sites (goatse or tubgirl anyone?) and hardcore porn sites.</p>
<p>There&#8217;s also a good write-up on the Sophos blog here with screen-shots:</p>
<p><a href="http://www.sophos.com/blogs/gc/g/2010/09/21/twitter-onmouseover">Twitter &#8216;onmouseover&#8217; security flaw widely exploited</a></p>
<p>A full post on the issue from Twitter is available here:</p>
<p><a href="http://blog.twitter.com/2010/09/all-about-onmouseover-incident.html">All about the &#8220;onMouseOver&#8221; incident</a></p>
<p>I like how they are responsible about such things and don&#8217;t try to hide them. If you are on Twitter and you want the latest updates about such matters you should follow the <a href="http://twitter.com/safety">@safety</a> account.</p>
<p>Source: <a href="http://www.networkworld.com/news/2010/092110-twitter-hack-sees-websites-opened.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Twitter+onMouseOver+XSS+Exploit+Causes+Chaos+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2955+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/09/twitter-onmouseover-xss-exploit-causes-chaos/&amp;t=Twitter+onMouseOver+XSS+Exploit+Causes+Chaos" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/09/twitter-onmouseover-xss-exploit-causes-chaos/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/09/twitter-onmouseover-xss-exploit-causes-chaos/&amp;title=Twitter+onMouseOver+XSS+Exploit+Causes+Chaos" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/09/twitter-onmouseover-xss-exploit-causes-chaos/&amp;title=Twitter+onMouseOver+XSS+Exploit+Causes+Chaos" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/09/twitter-onmouseover-xss-exploit-causes-chaos/&amp;title=Twitter+onMouseOver+XSS+Exploit+Causes+Chaos" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/09/twitter-onmouseover-xss-exploit-causes-chaos/&amp;title=Twitter+onMouseOver+XSS+Exploit+Causes+Chaos" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F09%2Ftwitter-onmouseover-xss-exploit-causes-chaos%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/09/twitter-onmouseover-xss-exploit-causes-chaos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter Hack Spreads P*rn Trojan</title>
		<link>http://www.darknet.org.uk/2009/06/twitter-hack-spreads-prn-trojan/</link>
		<comments>http://www.darknet.org.uk/2009/06/twitter-hack-spreads-prn-trojan/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 10:45:59 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[guy kawasai twitter hack]]></category>
		<category><![CDATA[guy kawasaki]]></category>
		<category><![CDATA[guy kawasaki twitter]]></category>
		<category><![CDATA[leighton meester]]></category>
		<category><![CDATA[leighton meester sex tape]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[twitter hack]]></category>
		<category><![CDATA[twitter hacked]]></category>
		<category><![CDATA[twitter security]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[web-application-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1888</guid>
		<description><![CDATA[I had a spam tweet appear in my stream a while back and like Guy Kawasaki I also had absolutely no idea where it came from. Perhaps some kinda XSS flaw in Twitter when I visited a site that spawned the message (in a hidden iframe perhaps). It wouldn&#8217;t be the first time Twitter was [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>I had a spam tweet appear in my stream a while back and like Guy Kawasaki I also had absolutely no idea where it came from.</p>
<p>Perhaps some kinda <a href="http://www.darknet.org.uk/tag/xss">XSS</a> flaw in Twitter when I visited a site that spawned the message (in a hidden iframe perhaps).</p>
<p>It wouldn&#8217;t be the first time <a href="http://www.darknet.org.uk/tag/twitter/">Twitter</a> was having security problems, just this time it&#8217;s not something that&#8217;s gone public. Spammers are using it to entice people to watch Sex Tapes and visit affiliate sites.</p>
<blockquote><p>Former Apple Macintosh evangelist Guy Kawasaki posts Twitter messages about a lot of different thing, but the message he put up on Tuesday afternoon was really out of character.</p>
<p>&#8220;Leighton Meester sex tape video free download!&#8221;</p>
<p>His message included a link that, after some further clicking, landed Kawasaki&#8217;s followers on a fake porn site where online criminals try to install a nasty Trojan horse program on victim&#8217;s computers. And in an interesting twist, the program attacks both Mac and Windows users.</p>
<p>Kawasaki, a well known entrepreneur who is now a a managing director of Garage Technology Ventures, isn&#8217;t the only person whose account was misused during a new round of Twitter hacking Tuesday, but with nearly 140,000 followers he&#8217;s the most high-profile. Meester, the star of the TV Show GossipGirl is also said to be the subject of a homemade sex tape that is reportedly in circulation.</p></blockquote>
<p>Apparently 1,600 people clicked on the link, probably because most people don&#8217;t know who Leighton Meester is, they would have had more luck with Lady Gaga or Britney Spears sex tapes :D</p>
<p>They would have better results hijacking his account, but I suspect they didn&#8217;t have access. He just clicked the wrong link or viewed the wrong site once and that spawned the message.</p>
<p>It&#8217;s possible there could a flaw in the Twitter API too and with some kinda fuzzing or brute force you can broadcast messages.</p>
<blockquote><p>It&#8217;s not clear how hackers managed to gain access to Kawasaki&#8217;s account &#8212; security experts say that he and others may have fallen victim to earlier Twitter phishing attacks, where attackers tried to trick victims into logging into fake Twitter sits in hopes of stealing their login credentials.</p>
<p>Other hacked accounts are being used to to promote pornographic Web sites. Victims include an Arizona political blogger, an up-and-coming Canadian musician, and a Gay news site. (note, some of these Twitter pages still include pornographic and possibly malicious links)</p>
<p>Twitter has had its share of security problems over the past months. Earlier this year someone gained access to the Twitter accounts of U.S. President Barack Obama, Britney Spears, and others.</p>
<p>Recently scammers have become more aggressive on the site. They will set up new accounts and post spam messages on hot topics in hopes of gaining clicks when people search through Twitter. </p></blockquote>
<p>Twitter have recently set up a system for <a href="http://twitter.com/help/verified">verified accounts</a>, I hope they also ensure these accounts stay secure and in the hands of the right people.</p>
<p>It&#8217;ll be interesting to see what turns up, if someone makes another flaw in Twitter public.</p>
<p>I hope they do as it&#8217;ll make the system more secure for everyone.</p>
<p></p>
<p>Source: <a href="http://www.pcworld.com/businesscenter/article/167253/high_profile_twitter_hack_spreads_porn_trojan.html">PCWorld</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Twitter+Hack+Spreads+P%2Arn+Trojan+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1888+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/twitter-hack-spreads-prn-trojan/&amp;t=Twitter+Hack+Spreads+P%2Arn+Trojan" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/06/twitter-hack-spreads-prn-trojan/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/twitter-hack-spreads-prn-trojan/&amp;title=Twitter+Hack+Spreads+P%2Arn+Trojan" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/twitter-hack-spreads-prn-trojan/&amp;title=Twitter+Hack+Spreads+P%2Arn+Trojan" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/06/twitter-hack-spreads-prn-trojan/&amp;title=Twitter+Hack+Spreads+P%2Arn+Trojan" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/twitter-hack-spreads-prn-trojan/&amp;title=Twitter+Hack+Spreads+P%2Arn+Trojan" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F06%2Ftwitter-hack-spreads-prn-trojan%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/twitter-hack-spreads-prn-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

