8 ms·
Twitter spam wave
- ossreality 13y ago"Twitter for iPhone API compromised?" Is that supposed to... you know... mean something?
- mntmn 13y agoMy own timeline was compromised, so I started looking into this. A fake tweet was posted on my behalf with "Twitter for iPhone" as the source. I don't have an iPhone since quite some time, but I used to have the app back in the day and never revoked access until now.
- mntmn 13y agoUpdate: Automatically got an email from twitter saying: > Twitter believes that your account may have been compromised by a website or service not associated with Twitter. We've reset your password to prevent others from accessing your account. The spam tweet posted on my behalf was automatically deleted. (Edit: For reference, the spammy link pointed to a domain called apaloreto dot info, but led to a 404 in my case)
- icpmacdo 13y agoSo has it been identified what you hit to cause a highjack of your account?
- drmarianus 13y agoI use a Nexus 5 but recently I got a notification from MyPermissions [0] saying "Twitter for iPhone gained access to certain permissions." I checked it and it said it had rights to post on my behalf. I quickly removed all permissions as this was rather suspicious. I would recommend doing the same. [0] http://mypermissions.com/ http://mypermissions.com/
- peterwwillis 13y agoHave you ever owned an iPhone and installed the Twitter app? If not, have you ever installed a Twitter app on your Nexus? If Twitter used the same app token for iPhone and Nexus twitter apps, and your Nexus twitter auth cred was stolen, they could use an implementation of the twitter client API with the iPhone user-agent, then post with your creds. I have absolutely no idea if any of that is accurate, but it might explain the access.
- lawl 13y agoLuckily my timeline was not affected. However, I wonder, shouldn't Twitter be able to pick these messages up automatically fairly fast, after (I assume) hundreds if not thousands of users have flagged them? Also, the spammers can't have unlimited IP's. Twitters anti spam kinda seems to lag back behind E-Mail (subjectively). Is there a reason the same techniques used in E-Mail aren't applicable to Twitter?
- chimeracoder 13y ago> Is there a reason the same techniques used in E-Mail aren't applicable to Twitter? Twitter relies on very low latency - ie, once you tweet something, if it a whole minute to appear in your friends' timelines, it could already have lost much of its value. Lots of spam reduction techniques introduce latency to levels that are unacceptable to Twitter's use case. I'm not sure why it didn't catch these, but I can imagine why the same techniques aren't applicable in general.
- orf 13y agoSure, but couldn't they run something that cleans up already posted tweets? That wouldn't introduce any latency while posting but would still (eventually) get rid of them automatically and hopefully pretty fast.
- elwell 13y agoI think they are. Most of the search results I'm seeing are only up until a minute ago.
- mntmn 13y agoThey do – they deleted a tweet from my timeline.
- CWuestefeld 13y agoIf my twitter account was compromised and used to send spam, I think the way I'd discover this is by seeing the record of tweets sent by the false "me". If those are being culled, then how will I know that my account has been compromised?
- mahouse 13y agoThe bit.ly link is marked as spam and shows a warning, and then the shortened link doesn't load at all. The spammer failed :P
- themoonbus 13y agoI additionally went through a twitter warning before I got to the bit.ly warning
- eponeponepon 13y agoI am not a Twitter user. Can anyone explain what I'm looking at here? The outcome of malicious Javascript?
- deleted 13y ago[deleted]
- mntmn 13y agoMy spam tweet had "Twitter for iPhone" API access as the source, and I wasn't using an iOS device at the time it was posted. It's unclear what actually happened.
- thefreeman 13y agoyou don't need to be using an iOS device for someone to use your devices authentication token to access your account. Sounds like perhaps a a vulnerability leaking oauth tokens in the iOS client?
- girvo 13y agoOr something to do with Twitter's iPhone integration having an issue, allowing someone to create credentials on your behalf.
- s1kx 13y agoI would assume it's just sent through the API with the iOS App's app credentials (they are open and out there). That specific set of app credentials allows the OAuth endpoint for email + password sign in through the API. Maybe some other database got hacked and the user credentials were used on twitter.
- bad_user 13y agoI just tried deactivating it, but couldn't - apparently "Twitter for iPhone" needs to be deactivated on the device itself. What's up with that?
- enthdegree 13y agoFunny how now the search is full of tweets referencing the "Twitter Spam Wave"
- Houshalter 13y ago"Seriously the best thing I have ever tried" - what on Earth would be the purpose of spamming that?
- aalpbalkan 13y agoProof of concept? The attacker might use something else in the future.
- jhdkjqhkjqhwk 13y agoI don't twitter but whenever I'm shown tweet I'm astounded at the amount of redirection involved in linking.
- rplnt 13y agoThis link to search over dynamic content is as pointless as those "service x is down" linking to service x.
- Kiro 13y agoI don't see anything special. Have the tweets been removed? What was it?