Trilight Zone Forum Index Trilight Zone
Privacy & Anonymity is our specialty !
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

WHID 2009-2: Twitter accounts of the famous hacked (Updated)

 
Post new topic   Reply to topic    Trilight Zone Forum Index -> HPAV & Related
Author Message
trihub
Sergeant


Joined: 04 Dec 2006
Posts: 180

PostPosted: Thu Aug 27, 2009 2:14 pm    Post subject: WHID 2009-2: Twitter accounts of the famous hacked (Updated) Reply with quote

Source: http://www.xiom.com/whid/blog

Update (Jan 11th 2009) - The hacker bragged about the hack and revealed that it was a brute force dictionary attack against an administrator account. Twitter does not block repetitive login failures therefore enabling brute force attacks. We are still leaving the incident classification "insufficient authentication" in addition to brute force as we feel an administration interface should have additional authentication mechanism and not just a password.

Twitter announced that a hacker broke into 33 accounts including Obama's now inactive twitter. The hack is a result of a flaw in a web based support tool used by twitter, which where evidently accessible externally without proper authorization.

It is important to note that this incident is not related to Twitter phishing attack which occurred on the previous weekend.

This incident highlights the issue of public facing administration interfaces, which often combine strong functionality with lesser attention to quality and therefore security. As organizations virtualize, those interfaces become available over the Internet, often without sufficient protection.

You can read some of the funny things that the hacker published in different twitters on Read Write Web.
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Trilight Zone Forum Index -> HPAV & Related All times are GMT
Page 1 of 1

 


Powered by phpBB © 2001, 2005 phpBB Group