Attacks/Breaches
4/24/2013
09:27 AM
Connect Directly
RSS
E-Mail
50%
50%

Twitter Preps Two Factor Authentication After AP Hoax

Security move follows a rash of high-profile account takeovers, including a hoax tweet from the Associated Press' account about White House explosions.

"Breaking: Two Explosions in the White House and Barack Obama is injured."

So claimed a tweet from The Associated Press account, which counts 1.9 million followers, posted at 1:07:50 p.m. Eastern time Tuesday. Just minutes later, however, new tweets issued from other AP accounts began to deny that report.

But the news still seemed to trigger a downturn in the Dow Jones Industrial Average, and the hoax tweet "briefly erased $200 billion of value" from U.S. stock markets on Tuesday, reported The Wall Street Journal. It said the downturn had been triggered, at least in part, by automated trading systems that use "so-called algorithms that automatically buy and sell shares after scanning news feeds." Those algorithms reportedly reacted to the fake news by waiting to buy new stocks.

In a Tuesday press briefing, White House spokesman Jay Carney confirmed that there had been no explosions, and that the president was safe. "I was just with him," he said. The FBI is reportedly investigating the hoax tweet and related Twitter account takeovers.

[ Is "cyberwarfare" as bad as it sounds? Read Cyber Strikes Like Nuclear Bombs, Says Chinese General. ]

Following the hoax tweet, the AP Tuesday self-reported that "The AP has disabled its other Twitter accounts following the attack."

Tuesday evening, a hacktivist group known as the Syrian Electronic Army claimed credit for the AP account takeovers. "Ops! @AP get owned by Syrian Electronic Army! #SEA #Syria #ByeByeObama" read a tweet posted to the group's @Official_SEA6 Twitter account. The group also claimed credit via its syrianelectronicarmy.com website for takeovers of the @AP and @AP_Mobile accounts.

Interestingly, numerous AP accounts remained suspended as of early Wednesday morning. "It's a bit surprising that 12 hours after the hack, the Twitter account @AP is still suspended," said Mikko Hypponen, chief research officer at F-Secure, via Twitter. But later Wednesday morning, the @AP account was again live.

Other still-suspended accounts included @AP_Mobile, @AP_Fashion, @AP_Images, @AP_NFL, @AP_Country, @AP_Travel and @APStylebook. The delay in AP resuming control of those accounts suggests the news agency is still attempting to identify how attackers seized the accounts, or else remediate all machines that may have been compromised by attackers

The AP has yet to disclose how the attackers compromised its Twitter accounts, but released a statement saying that "the attack on AP's Twitter account and the AP Mobile Twitter account was preceded by phishing attempts on AP's corporate network." It didn't specify if those phishing attacks used malware attached to emails, emails with links to websites that could launch drive-by attacks that attempted to exploit browser vulnerabilities, or both.

But AP spokesman Paul Colford told The New York Times that all of these phishing attacks had been blocked.

In the wake of the White House bomb hoax, Wired reported Tuesday that Twitter is now testing a two-factor authentication system internally and plans to roll it out incrementally to users. The publication cited no source for that information, and said it had learned of no timeline for when such a rollout might begin.

"Until Twitter implements that, you can continue to expect to see high-profile accounts be hijacked with some regularity," said Christopher Budd, threat communications manager at Trend Micro, in a blog post.

A Twitter spokeswoman didn't immediately respond to a request for comment, emailed outside normal business hours, about either the AP account takeovers or reports that the company is beta-testing a two-factor authentication system.

Twitter in February advertised a job for an engineer with expertise in "multifactor authentication and fraudulent login detection," following a watering hole attack that compromised up to 250,000 users' accounts.

Why did the Syrian Electronic Army issue the fake tweet? According to the group's website, its mission includes redressing "the campaigns led by the Arab media and Western on our Republic by broadcasting fabricated news about what is happening in Syria." The group is widely seen as being sympathetic to the regime of Syrian president Bashar al-Assad.

The White House bomb tweet hoax follows the group's takeover in recent days of multiple CBS Twitter accounts, including 60 Minutes, and posting tweets with links to websites that launched drive-by attacks. The group this week also seized multiple accounts relating to worldwide soccer governing body FIFA. Those takeovers followed the group recently taking control of the National Public Radio Twitter feed as well as multiple BBC Twitter accounts.

As of Wednesday morning, the Syrian Electronic Army account @Official_SEA6 had been suspended by Twitter, but the group appeared to have registered @Official_SEA7, which remained active, although had no posts.

What lessons can be learned from the latest Twitter corporate account takeovers? "If you manage a Twitter handle, this underscores the importance of using a strong password, running up-to-date security software, not clicking on links, and being very, very cautious when working with Twitter credentials," said Trend Micro's Budd.

Also beware reusing passwords, which is a widespread practice. According to a study released Tuesday by British communications regulator Ofcom, a survey of 1,805 people over the age of 15 found that 55% "use the same password for most, if not all, websites."

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
4/24/2013 | 11:35:31 PM
re: Twitter Preps Two Factor Authentication After AP Hoax
The attack is a testament to Twitter's influence, but it's also interesting to see how correctly the social sphere course-corrected.

Drew Conry-Murray
Editor, Network Computing
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2003-1598
Published: 2014-10-01
SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.

CVE-2011-4624
Published: 2014-10-01
Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.

CVE-2012-0811
Published: 2014-10-01
Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files gene...

CVE-2012-5485
Published: 2014-09-30
registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.

CVE-2012-5486
Published: 2014-09-30
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Chris Hadnagy, who hosts the annual Social Engineering Capture the Flag Contest at DEF CON, will discuss the latest trends attackers are using.