<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; twitter hacking</title>
	<atom:link href="http://www.darknet.org.uk/tag/twitter-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Twitter Major Password Reset After Phishing Attack</title>
		<link>http://www.darknet.org.uk/2010/02/twitter-major-password-reset-after-phishing-attack/</link>
		<comments>http://www.darknet.org.uk/2010/02/twitter-major-password-reset-after-phishing-attack/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 08:10:58 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[get followers fast]]></category>
		<category><![CDATA[hacking twitter]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[password-hacking]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[twitter hacking]]></category>
		<category><![CDATA[twitter phishing]]></category>
		<category><![CDATA[twitter privacy]]></category>
		<category><![CDATA[twitter scam]]></category>
		<category><![CDATA[twitter security]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2495</guid>
		<description><![CDATA[Twitter has come under attack fairly frequently in recent months, which is not surprising considering the explosive growth of the platform and the sheer number of users it has. If you are a Twitter use you may have noticed many people had their password reset automatically yesterday, Twitter today announced the reason for this on [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p><a href="http://www.darknet.org.uk/tag/twitter/">Twitter</a> has come under attack fairly frequently in recent months, which is not surprising considering the explosive growth of the platform and the sheer number of users it has.</p>
<p>If you are a Twitter use you may have noticed many people had their password reset automatically yesterday, Twitter today announced the reason for this on their status site here:</p>
<p><a href="http://status.twitter.com/post/367671822/reason-4132-for-changing-your-password">Reason #4132 for Changing Your Password</a></p>
<p>It&#8217;s a fairly intricate scam where someone has spent a lot of time effort and exhibited patience in harvesting all of these accounts.</p>
<blockquote><p>Officials at Twitter linked the resetting of passwords to a malicious Torrent sites and other schemes. According to Twitter, the company began its investigation after noticing a surge in followers for certain accounts during the past five days. Twitter revealed more details about the phishing attacks that caused the company to reset the passwords on some user accounts today.</p>
<p>According to Twitter Director of Trust and Safety Del Harvey, there was a sudden surge in followers for certain accounts during the last five days. For that reason, the company decided to push out a password reset to the accounts, he said. After launching an investigation, Twitter officials linked part of the problem to malicious torrent sites.</p>
<p>“It appears that for a number of years, a person has been creating torrent sites that require a login and password as well as creating forums set up for torrent site usage and then selling these purportedly well-crafted sites and forums to other people innocently looking to start a download site of their very own,” Harvey blogged. “However, these sites came with a little extra — security exploits and backdoors throughout the system. This person then waited for the forums and sites to get popular and then used those exploits to get access to the username, email address, and password of every person who had signed up.”</p></blockquote>
<p>The main crux of the story is, if you&#8217;ve signed up for any 3rd party private torrent trackers or forums, you&#8217;d better go and change your e-mail address and password there. Especially if you were stupid enough to use the same password you use for other sites (such as Twitter).</p>
<p>The trend seems to be continuing with people using the same username, e-mail and password (or at least a variation of the same password) across multiple sites.</p>
<p>I&#8217;m pretty sure however, everyone reading this site doesn&#8217;t do that as we are fully aware of the danger involved.</p>
<blockquote><p>“Additional exploits to gain admin root on forums that weren’t created by this person also appear to have been utilized; in some instances, the exploit involved redirecting attempts to access the forums to another site that would request log-in information,” he continued. &#8220;This information was then used to attempt to gain access to third party sites like Twitter.”</p>
<p>Harvey stated that Twitter has not identified all of the torrent forums involved, but urged anyone who has signed up for one built by a third party to change their password there.</p>
<p> “The takeaway from this is that people are continuing to use the same email address and password (or a variant) on multiple sites,” he blogged. “Through our discussions with affected users, we’ve discovered a high correlation between folks who have used third party forums and download sites and folks who were on our list of possibly affected accounts.”</p>
<p>Not all of the accounts affected were linked to Torrent sites, Harvey added. Earlier today, a Twitter spokesperson told eWEEK that some users had signed up for &#8220;get followers fast schemes.&#8221;</p></blockquote>
<p>I see a LOT of people on Twitter falling for these &#8220;Get followers fast&#8221; or &#8220;Get 1000 followers NOW&#8221; schemes which require them to give their login credentials to 3rd party sites.</p>
<p>Of course after that the sites use their account to send spam DMs or tweets and often end up in the user account getting locked for spamming.</p>
<p>This of course follows the <a href="http://www.darknet.org.uk/2009/09/twitter-dm-phishing-scam/">Twitter DM Phishing Scam</a> and the time the <a href="http://www.darknet.org.uk/2009/11/ssl-renegotiation-bug-succesfully-used-to-attack-twitter/">SSL Renegotiation Bug was used on Twitter</a>.</p>
<p>Darknet is on Twitter, if you wish to follow us you can do so here: <a href="http://www.twitter.com/THEdarknet">http://www.twitter.com/THEdarknet</a></p>
<p></p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Twitter-Details-Phishing-Attacks-Behind-Password-Reset-273647/">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Twitter+Major+Password+Reset+After+Phishing+Attack+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2495+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/02/twitter-major-password-reset-after-phishing-attack/&amp;t=Twitter+Major+Password+Reset+After+Phishing+Attack" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/02/twitter-major-password-reset-after-phishing-attack/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/02/twitter-major-password-reset-after-phishing-attack/&amp;title=Twitter+Major+Password+Reset+After+Phishing+Attack" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/02/twitter-major-password-reset-after-phishing-attack/&amp;title=Twitter+Major+Password+Reset+After+Phishing+Attack" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/02/twitter-major-password-reset-after-phishing-attack/&amp;title=Twitter+Major+Password+Reset+After+Phishing+Attack" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/02/twitter-major-password-reset-after-phishing-attack/&amp;title=Twitter+Major+Password+Reset+After+Phishing+Attack" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F02%2Ftwitter-major-password-reset-after-phishing-attack%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/02/twitter-major-password-reset-after-phishing-attack/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Using Twitter for Data Mining and Information Gathering</title>
		<link>http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/</link>
		<comments>http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 10:46:31 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[5and2fish]]></category>
		<category><![CDATA[data-mining]]></category>
		<category><![CDATA[hacking twitter]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[PeopleBrowsr]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[twitter data mining]]></category>
		<category><![CDATA[twitter hacking]]></category>
		<category><![CDATA[twitter information gathering]]></category>
		<category><![CDATA[twitter privacy]]></category>
		<category><![CDATA[Twitter Spectrum]]></category>
		<category><![CDATA[Twitter Venn]]></category>
		<category><![CDATA[TwitterFriends]]></category>
		<category><![CDATA[Twitturly]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1423</guid>
		<description><![CDATA[We&#8217;ve mentioned Twitter a few times lately as it has become a larger and larger part of the social web and the premier &#8216;micro-blogging&#8217; platform. There was a recent Phishing issue on Twitter and before that Twitter Jacking and a CSRF bug that allowed auto-following. Due to the large update of Twitter, the amount of [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>We&#8217;ve mentioned <a href="http://www.darknet.org.uk/tag/twitter/">Twitter</a> a few times lately as it has become a larger and larger part of the social web and the premier &#8216;micro-blogging&#8217; platform.</p>
<p>There was a recent <a href="http://www.darknet.org.uk/2009/01/phishing-attacks-hits-twitter-users-utilising-direct-messages/">Phishing issue on Twitter</a> and before that <a href="http://www.darknet.org.uk/2008/11/twitter-squatting-the-new-domain-jacking/">Twitter Jacking</a> and a <a href="http://www.darknet.org.uk/2008/09/csrf-vulnerability-in-twitter-allows-forced-following/">CSRF bug that allowed auto-following</a>.</p>
<p>Due to the large update of Twitter, the amount of datable available on the site and it&#8217;s easily searchable nature it has become a great platform for data-mining and information gathering (the first and sometimes most important parts of any pen test/vuln ass or security test).</p>
<blockquote><p>Twitter is fun. It&#8217;s also a powerful research tool. People increasingly use Twitter to share advice, opinions, news, moods, concerns, facts, rumors, and everything else imaginable. Much of that data is public and available for mining.</p>
<p>Here&#8217;s how to use Twitter to gather useful information about topics, companies, and individuals. I&#8217;ll cover native Twitter features, as well as third-party tools with catchy names, such as 5and2fish, Twitter Venn, TwitterFriends, PeopleBrowsr , Twitturly, Twitter Spectrum, and others.</p>
<p>Most of the techniques mentioned here don&#8217;t require you to be a registered Twitter user. If you use Twitter, consider what data tidbits you release there, and whether you need to be more careful.</p></blockquote>
<p>People don&#8217;t tend to be so careful or post in such a considered manner when using Twitter as the tidbits posted are so short and off-the-cuff.</p>
<p>This leads to an interesting source of information for people like us doing research about an individual or organization. You can really get a good gauge on the publics feelings for a certain topic too by searching Twitter for relevant keywords.</p>
<p>For example if you search Twitter for &#8216;<a href="http://search.twitter.com/search?q=darknet">Darknet</a>&#8216; you can see some people mentioning our posts and one guy pretty consistently re-syndicating our content onto the micro-blogging platform.</p>
<blockquote><p>As you gather information on Twitter, be mindful of others attempting to manipulate you into arriving at their conclusions by feeding you misinformation. Cross-check data and understand its sources. For more on this, see Is Twitter A Market Manipulator&#8217;s Dream on the TwiTip blog. If the topic of reputational attacks interests you, also look at the SpinHunters blog.</p>
<p>If using Twitter to share information and stay in touch with your friends, be mindful of how others might misuse what you reveal about yourself, others, or your company. In the words of Wired magazine&#8217;s Steven Levy, &#8220;No matter how innocuous your individual tweets, the aggregate ends up being the foundation of a scary-deep self-portrait. It&#8217;s like a psychographic version of strip poker&#8211;I&#8217;m disrobing, 140 characters at a time.&#8221;</p></blockquote>
<p>It&#8217;s an article well worth reading if you are a Twitter user or not, if you are an infosec professional it gives you another source to search when you are doing information gathering or data-mining tasks.</p>
<p>The Internet is always evolving along with the way people use it, as it becomes a more social platform &#8211; more information is bound to be &#8216;<em>exposed</em>&#8216; online &#8211; for us to find..</p>
<p></p>
<p>Source: <a href="http://isc.sans.org/diary.html?storyid=5728&#038;rss">SANS ISC</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Using+Twitter+for+Data+Mining+and+Information+Gathering+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1423+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;t=Using+Twitter+for+Data+Mining+and+Information+Gathering" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;title=Using+Twitter+for+Data+Mining+and+Information+Gathering" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;title=Using+Twitter+for+Data+Mining+and+Information+Gathering" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;title=Using+Twitter+for+Data+Mining+and+Information+Gathering" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/&amp;title=Using+Twitter+for+Data+Mining+and+Information+Gathering" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F01%2Fusing-twitter-for-data-mining-and-information-gathering%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/01/using-twitter-for-data-mining-and-information-gathering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

