Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection » Password guessing attack exposed in Twitter pwn
Closed Thread
Old 01-07-2009, 02:17 PM   #1 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,180

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Password guessing attack exposed in Twitter pwn

Miscreants broke into Twitter's admin system on Sunday night using a simple password guessing hack, it has emerged.
A teenage hacker, known in the digital underground as GMZ, claims he obtained access to the micro-blogging site’s admin controls using a brute force dictionary attack. After guessing the login identity of an administrator, in part based on the large number of people she followed, GMZ ran an automated password guessing program overnight to reveal that 'Crystal' used the eminently guessable password of "happiness". The 18-year-old student then used these details to offer up access to Twitter accounts on request through Digital Gangster, an underground hacker forum, Wired reports.
The move enabled griefers to break into the Twitter feeds of the likes of Britney Spears, Fox News and US President-Elect Barack Obama on Monday to push out bogus messages. GMZ sat on the sidelines during this attack because he had failed to use a proxy during his password cracking attack, making him more at risk of identification.
The man behind the mischief offered a instant message interview with Wired after other hackers implicated him in the attack. GMZ backed up the story that he broke into Twitter's admin system by offering a video of the initial attack, which has since been published on YouTube.

The attack itself was made easy not just because of the use of a weak password on a key account, but because Twitter failed to implement the kind of password-guessing hurdles that are commonplace elsewhere on the net - even in far less sensitive environments such as Gmail and Hotmail logins - so that multiple unchallenged log-in attempts were possible. Access to the compromised admin account allowed the login credentials of other accounts to be reset.
"Twitter and other websites should be able to tell when hackers are trying to brute-force their way past a password," said Graham Cluley, senior technology consultant at Sophos. "GMZ says he ran his automatic password guessing program overnight before it finally broke its way in.
"There’s no reason why Twitter couldn’t, say, notice that someone has entered the wrong password three times in a row, and then insist they wait 15 minutes before trying to log in again.
"Twitter could help avoid this problem by insisting that passwords are not known dictionary words, or forcing the use of numbers and other characters - such as underlines, exclamation marks and percentages - in users' chosen passwords."
Twitter co-founder Biz Stone confirmed a dictionary attack was used to gain access to an administrative account but declined to answer further questions, including queries about the duration of the breach.
GMZ, who reports he's been hacking for around three years, has previously claimed responsibility for breaking into the YouTube account of teen actress Miley Cyrus. The latest attack on Twitter reportedly used the same attack script.

Password guessing attack exposed in Twitter pwn ? The Register
__________________
Osiris is online now  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Twitter accounts of Obama, Britney Spears hacked Osiris Virus - Spyware Protection / Detection 0 01-05-2009 09:08 PM
Fake Twitter profile punts Orkut attack Osiris Virus - Spyware Protection / Detection 0 09-09-2008 01:02 PM
Twitter Trojan targets tossers Osiris Virus - Spyware Protection / Detection 0 08-05-2008 08:03 AM