Vulnerabilities / Threats
6/15/2009
05:00 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Twitter Security Heating Up In July

In an effort to raise awareness of browser security flaws, one researcher wants to post a vulnerability every day that shows the soft underside of the Fail Whale.

For Twitter users, the month of living dangerously begins in two weeks. Come July, Israeli security researcher Aviv Raff plans to publish a new Twitter security vulnerability every day, for the duration of the month.

Raff participated in the "Month of Browser Bugs" initiative in July 2006. It was an effort to raise awareness of browser security flaws. Now he wants to shine the spotlight on Twitter with the "Month of Twitter Bugs."

"Each day I will publish a new vulnerability in a third-party Twitter service on the twitpwn.com Web site," Raff explained on his blog. "As those vulnerabilities can be exploited to create a Twitter worm, I'm going to give the third-party service provider and Twitter at least 24 hours heads-up before I publish the vulnerability."

Raff says that while he has more than enough vulnerabilities to publish one every day in July, he nonetheless welcomes submissions.

Twitter did not respond to a request for comment.

Raff, in a previous blog post, observed that Twitter's most significant security problem is its API, which can be abused to create worms.

In May, he created proof-of-concept code that exploits a vulnerability in the Web site twitpic.com, which uses the Twitter API.

Twitter has weathered several security problems already this year. In April, a Twitter worm created by a 17-year-old infected at least 190 accounts and generated almost 10,000 spam tweets.

Also in April, a Twitter administrative account was hacked. The hacker who claimed responsibility posted screenshots of several celebrity Twitter accounts accessed through the compromised administrative account.

There have been other incidents too: In March, about 750 Twitter accounts were hacked and used to send spam. And in January, 33 Twitter accounts associated with celebrities were hacked through a brute-force password attack.

In response to the April account hack, Twitter co-founder Biz Stone said the company would conduct an independent security audit of its internal systems and would deploy additional anti-intrusion measures. To date, the company has not provided an update on its security efforts.


InformationWeek Analytics and DarkReading.com have published an independent analysis of security outsourcing. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3352
Published: 2014-08-30
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an "iFrame vulnerability," aka Bug ID CSCuh...

CVE-2014-3908
Published: 2014-08-30
The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2010-5110
Published: 2014-08-29
DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

CVE-2012-1503
Published: 2014-08-29
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.

CVE-2013-5467
Published: 2014-08-29
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM)...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.