Twitter Closes Hole After Attack Hits Up To 500K Users
chicksdaddy writes "Twitter closed an ugly cross site scripting hole in its Web page Tuesday morning, but not until a fast moving attack, including at least two Twitter worms, compromised hundreds of thousands of user accounts. At its height, the attacks were hitting 100 Twitter users each second, putting estimates of the total number of victims at around 500,000 according to researchers at Kaspersky Lab."
How complicated is it to write somewhat secure software that processes 140 character messages?
Was I too late to the party? I tried the exploit out at about 7 hours ago (with the malicious code removed) and it never worked for me. I then went to accounts that were reported infected and couldn't get any results. Was I lucky or just unintentionally more secure somehow?
Really,I know a lot of people seem to be using twitter, but I just don't get it. Am I too old? Hell, I don't actually know anyone using it. At least I don't think I do.
Why are people so interested to read an internet based text message? Is it really better than reading a well thought out and reasoned article about something?
More and more I see on all these tech news sites and blogs that they heard from so and so's tweet that such and such will be released with this and this. Then, all the other news sites link to the first blog who is using twitter as a source of information.
Since when is a text message a reliable source of information?
This was covered in the original post this morning. Nothing new in FTA versus the comments in the other one...
Twitter closes hole after attack hits up to 500 000 of its users, known as twits.
...gets the worm and then tweets about it. ;-)
"There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed H
Twitter is RSS for imbeciles; why does anybody care about (140 characters and less) inane bullshit being "retweeted"?
People tweeted about the exploit, that's why it became so popular in the first place.
Anything that gets Twitter to shut its damn hole is a good thing IMHO.
- None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
In other words, advertise. OK, now I get it.
"A lot of people use it to link to full articles"
I thought Twitter was between two holes ... ??
http://30.media.tumblr.com/hnBdf3xhZn70lld3VLy3gSBUo1_400.jpg
No sig for you. YOU GET NO SIG!
Isn't it about time Twitter got it's own topic icon?
.
Prisencolinensinainciusol. Ol Rait!
...as if millions of chirping birds suddenly cried out in terror and were suddenly silenced.
More like peace and quiet for once... At the risk of careening off topic, anyone else think the web has become an unnecessarily noisy place? It's getting harder and harder to cut through the crap and meaningless prattle...
...hmm... I'd better shut up now....
There are two types of people in the world; those who believe there are two types of people, and those who don't.
This is a Belly Button Lint Story. If you use facebook, myspace or twitter, then you deserve to be hacked. What a complete waste of time.
My last tweet was "found belly button lint - story at bar later." Probably the most useful tweet in months across the entire system.
putting estimates of the total number of victims at around 500,000 according
What if each text costs ten cents, thats $50K of revenue for the telcos. Since "everyone knows" the actual cost of service is like a million of a cent per text, thats about $50K profit for the telcos.
"Science flies us to the moon. Religion flies us into buildings." - Victor Stenger
And this is why I use NoScript. Sweet, sweet XSS protection with large, annoying warning when you come across one.
I really don't get the twitter hate.
I don't like facebook, but I can see its value, particularly if you manage it right and use it to share news and photos with friends and family etc. there are other valuable uses, but I use the example.
I still dont use it.
I don't use bebo, or myspace, or facepalm or crotchpunch.
Doesn't mean I have to hate on them.
I use twitter in much the same way other people have mentioned. I don't follow twitter shitters. (people who tweet constantly about inane shite) But I do follow people who provide interesting information, along with people I know and a range of news sites from aljazeera to bbc, to the NZ news site stuff, to Scientific american, and a range of others!
I follow a range of people, and I Find twitter useful because i can fire up my smartphone, pull up my twitter client and get a "snapshot of the world" and that's really what it is, any big news event happens, anywhere in the world I would probably put money on the fact I'll hear about it before anyone who isn't on twitter and isn't directly affected.
XKCD did a great comic about how people could hear about an earthquake via twitter before the actual shockwaves hit them.
but in short, if you don't want to use twitter, then don't, but all that your raging anti-twitter stance says is "I tried twitter but nobody followed me back"
so obviously you had nothing to add, therefore thank you for not using the service, you've increased its value already!
"This is my Sig. there are many like it but this one is mine."
This is an old (for the web) type of attack. No web site should be vulnerable to this sort of thing because all web developers (including me) know to sanitize their inputs. If only in order to avoid a Bobby Tables incident
Best Slashdot Co
that's ~81 minutes or just under an hour and a half. When was their discovery of the issue? If that's 1.5 hours from becoming aware of the issue to closing it, it's not terrible. What time of day was it at the office doing the maintenance? Was it even in office hours when someone would be there?
Funnyhacks - Wierd, unusual, and fun hacks
So, twitter is a bit like IRC. Is there a web interface to an IRC server that works in a similar way to twitter? It seems a bit silly to re-invent a protocol that's like IRC, but with fewer characters per message.
Ask me about repetitive DNA
See Rudy Park, it the txt generation, which believes that instant information, no matter how shallow, is a good thing and actually faster then the old fashioned slow media... like when an aircraft crashed in Holland, twitterers were very proud that twitter reported it first. Except it didn't. The radio did.
It fits with a generation raised on txt and very short attention spans. For many, this rant is already far to long. And I say generation, but really mean a group because not all young people are twitter nuts and not all old people have escaped it. It is more of a culture. The current MTV crowd, shallow as hell but lots of meaningless info that gives the appearance of depth with actually containing any. It is CNN, they shout very loud they got the most and the latest news so it must be true despite that the actual news content is a single sentence repeated a hundred times over. Even ex-science channels got it with documentaries that are along the lines of "Shark got big teeth, see this big teethed shard which has big teeth. It is known that shark got big teeth and these teeth the shark got are big and etc etc". Yes thank you. 1 hour, 2-3 lines of zero content repeated in as many ways possible.
Twitter is for people that think every thought in their head should be instantly broadcast to the world and others who actually FOLLOW this. Don't know which is sadder. Writing about my breakfast or reading about someone elses.
BUT it is NOTHING new. Countless cafeteria's have seen similar vapid discussions. We are the chattering monkey.
I yesterday was faced with a discussion about online games for women. Is there a market? One person did not get it. SHE did not want to play games AFTER a hard day at the work... no indeed. BUT the market for that is HOME-MAKERS. NOT women with intresting jobs.
Twitter ain't for you. You got other methods of airing your thoughts including maybe not airing them at all. Some people choose differently.
Let them.
I live happily with twitter by not using it. It doesn't disturb me that someone else tweets about his bowel movements. Because it does not affect me. At least they are not loudly proclaiming about their operation in the seat next to me. MTV might be the most moronic thing ever, but I simply removed it from the list and never have to deal with it. The txt generation mostly passes me by. Why are you so upset with them?
MMO Quests are like orgasms:
You may solo them, I prefer them in a group.