<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tweeterism &#187; Twitter Security Issues</title>
	<atom:link href="http://tweeterism.com/category/twitter-security-issues/feed/" rel="self" type="application/rss+xml" />
	<link>http://tweeterism.com</link>
	<description></description>
	<lastBuildDate>Fri, 22 May 2009 14:36:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Twitter Hit With Evil Phishing Attacks (Again)</title>
		<link>http://tweeterism.com/twitter-hit-with-evil-phishing-attacks-again/</link>
		<comments>http://tweeterism.com/twitter-hit-with-evil-phishing-attacks-again/#comments</comments>
		<pubDate>Fri, 22 May 2009 07:57:21 +0000</pubDate>
		<dc:creator>tweeterism</dc:creator>
				<category><![CDATA[Twitter Security Issues]]></category>
		<category><![CDATA[twitter phishing]]></category>

		<guid isPermaLink="false">http://tweeterism.com/twitter-hit-with-evil-phishing-attacks-again/</guid>
		<description><![CDATA[
In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. 
Phishing is typically carried out by e-mail or instant messaging, and it often directs users to enter details at [...]


Related posts:<ol><li><a href='http://tweeterism.com/twistenfm-helps-you-discover-new-music-with-twitter/' rel='bookmark' title='Permanent Link: Twisten.fm Helps You Discover New Music with Twitter'>Twisten.fm Helps You Discover New Music with Twitter</a></li>
<li><a href='http://tweeterism.com/tweetree-a-better-way-to-view-your-twitter-stream/' rel='bookmark' title='Permanent Link: Tweetree: A Better Way to View Your Twitter Stream'>Tweetree: A Better Way to View Your Twitter Stream</a></li>
<li><a href='http://tweeterism.com/twtifave-how-to-find-out-who-favorites-your-tweets/' rel='bookmark' title='Permanent Link: Twtifave: How to Find Out Who Favorites Your Tweets'>Twtifave: How to Find Out Who Favorites Your Tweets</a></li>
<li><a href='http://tweeterism.com/who-were-the-users-that-joined-twitter-first/' rel='bookmark' title='Permanent Link: Who Were the Users that Joined Twitter First?'>Who Were the Users that Joined Twitter First?</a></li>
<li><a href='http://tweeterism.com/why-was-the-dalai-lamas-twitter-account-suspended/' rel='bookmark' title='Permanent Link: Why Was the Dalai Lama&#8217;s Twitter Account Suspended?'>Why Was the Dalai Lama&#8217;s Twitter Account Suspended?</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 1px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftweeterism.com%2Ftwitter-hit-with-evil-phishing-attacks-again%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftweeterism.com%2Ftwitter-hit-with-evil-phishing-attacks-again%2F" height="61" width="51" /></a></div><p><img src="http://tweeterism.com/wp-content/uploads/2009/05/twitter-phishing.png" alt="twitter phishing" /></p>
<p>In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. </p>
<p>Phishing is typically carried out by e-mail or instant messaging, and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. (<a href="http://en.wikipedia.org/wiki/Phishing">Wikipedia</a>)</p>
<p>Yesterday a series of phishing attacks were launched on Twitter, the goal of which was to steal the passwords of users and then use them to get other user passwords in order to send out links to another phishing site. Phishing attacks are usually launched on financial institutions like online banks and information-sensitive areas like gmail for maximum profit.</p>
<p>The end goal of this particular Twitter phishing attack was to make money by redirecting users to adult dating sites, so the scammers can earn money through an affiliate program.</p>
<p>In this case here&#8217;s a <a href="http://www.macworld.com/article/140740/2009/05/twitter_phish.html">lowdown on what happened</a>, pay attention because this is usually how most phishing attacks work: </p>
<blockquote><p>In the first Twitter phishing round, hackers created fake Twitter accounts and then started following legitimate Twitter users. Twitter notifies users when they have new followers, sending the user a link to the follower&#8217;s Twitter profile page. In this case, the profile page contained a link to a phishing site. So the victim, while investigating his new follower, would end up on the fake site Tvviter(.)com (this page is not safe to visit) where he would be asked to enter his Twitter username and password.</p>
<p>Once the phishers obtained their victim&#8217;s login credentials, they used them to launch the second round of attacks. In this round, they posted Twitter messages such as &#8220;hey check thiss out&#8221; or &#8220;Hey. there is this funny blog going around.&#8221; These messages include a <a href="http://twitpic.com/5mvve">link to another phishing site</a>.</p></blockquote>
<p>Here are some recommended <a href="http://countermeasures.trendmicro.eu/phish-twice-a-day-the-twitter-diet/">security precautions</a> should take note of: </p>
<ol>
<li>Always check the URL in the address bar before entering your credentials for any online service.</li>
<li>Never click links from friends if you don’t know where they lead</li>
<li>It seems obfuscated URLs are becoming ever more a tool of cybercriminals, you should consider using longurl as a browser plug-in to let you see the true destination of shortened URLs before you click on them.</li>
</ol>
<p>Which is also a reason why you should consider using <a href="http://www.tweetdeck.com/beta/">Tweetdeck</a> as your Twitter client because Tweetdeck has a feature which allows you to see the full URL of each shortened link before you click on it, very useful indeed.</p>


<p>Related posts:<ol><li><a href='http://tweeterism.com/twistenfm-helps-you-discover-new-music-with-twitter/' rel='bookmark' title='Permanent Link: Twisten.fm Helps You Discover New Music with Twitter'>Twisten.fm Helps You Discover New Music with Twitter</a></li>
<li><a href='http://tweeterism.com/tweetree-a-better-way-to-view-your-twitter-stream/' rel='bookmark' title='Permanent Link: Tweetree: A Better Way to View Your Twitter Stream'>Tweetree: A Better Way to View Your Twitter Stream</a></li>
<li><a href='http://tweeterism.com/twtifave-how-to-find-out-who-favorites-your-tweets/' rel='bookmark' title='Permanent Link: Twtifave: How to Find Out Who Favorites Your Tweets'>Twtifave: How to Find Out Who Favorites Your Tweets</a></li>
<li><a href='http://tweeterism.com/who-were-the-users-that-joined-twitter-first/' rel='bookmark' title='Permanent Link: Who Were the Users that Joined Twitter First?'>Who Were the Users that Joined Twitter First?</a></li>
<li><a href='http://tweeterism.com/why-was-the-dalai-lamas-twitter-account-suspended/' rel='bookmark' title='Permanent Link: Why Was the Dalai Lama&#8217;s Twitter Account Suspended?'>Why Was the Dalai Lama&#8217;s Twitter Account Suspended?</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://tweeterism.com/twitter-hit-with-evil-phishing-attacks-again/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Dangerous Clickjacking Hack for Twitter Revealed</title>
		<link>http://tweeterism.com/dangerous-clickjacking-hack-for-twitter-revealed/</link>
		<comments>http://tweeterism.com/dangerous-clickjacking-hack-for-twitter-revealed/#comments</comments>
		<pubDate>Wed, 04 Feb 2009 19:41:18 +0000</pubDate>
		<dc:creator>tweeterism</dc:creator>
				<category><![CDATA[Twitter Security Issues]]></category>
		<category><![CDATA[security clickjacking]]></category>

		<guid isPermaLink="false">http://tweeterism.com/?p=105</guid>
		<description><![CDATA[
Did you know that clicking on an innocent link on a webpage while logged into Twitter allows a malicious cracker to update your Twitter status without you knowing? This links is usually invisible or placed under a commonly used button.This is known as click jacking. 
An example of clickjacking on Twitter was revealed by James [...]


Related posts:<ol><li><a href='http://tweeterism.com/how-to-add-a-retweet-button-to-the-twitter-web-interface/' rel='bookmark' title='Permanent Link: How to Add a Retweet Button to the Twitter Web Interface'>How to Add a Retweet Button to the Twitter Web Interface</a></li>
<li><a href='http://tweeterism.com/creating-a-twitter-feed-for-conferences-and-events/' rel='bookmark' title='Permanent Link: Creating a Twitter Feed for Conferences and Events'>Creating a Twitter Feed for Conferences and Events</a></li>
<li><a href='http://tweeterism.com/twitter-magnets-create-poetry-and-share-it-on-twitter/' rel='bookmark' title='Permanent Link: Twitter Magnets: Create Poetry and Share it on Twitter!'>Twitter Magnets: Create Poetry and Share it on Twitter!</a></li>
<li><a href='http://tweeterism.com/combining-twitter-with-your-house-security-system/' rel='bookmark' title='Permanent Link: Combining Twitter With Your House Security System'>Combining Twitter With Your House Security System</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 1px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftweeterism.com%2Fdangerous-clickjacking-hack-for-twitter-revealed%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftweeterism.com%2Fdangerous-clickjacking-hack-for-twitter-revealed%2F" height="61" width="51" /></a></div><p><img src="http://tweeterism.com/wp-content/uploads/2009/02/clickjacking.jpg"/ alt="clickjacking" /></p>
<p>Did you know that clicking on an innocent link on a webpage while logged into Twitter allows a malicious cracker to update your Twitter status without you knowing? This links is usually invisible or placed under a commonly used button.This is known as <a href="http://en.wikipedia.org/wiki/Clickjacking/">click jacking</a>. </p>
<p>An example of clickjacking on Twitter was revealed by James Padolsey who also recommended that one install the <a href="http://noscript.net/">NoScript firefox addon</a> as a method of protection. <a href="http://james.padolsey.com/general/clickjacking-twitter/">See his article</a> to get an example of clickjacking in action. </p>
<blockquote><p>Using the basic technique of positioning an iframe over a button coupled with Twitter’s ’status’ URL parameter I have created a small demo which shows you just how serious (and annoying) this could be! It will only work if you’re currently logged into Twitter. </p></blockquote>
<p><a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=213000919">Via Dark Reading</a>, which also offers a quote from some researchers: </p>
<blockquote><p>Robert &#8220;RSnake&#8221; Hansen, who, along with fellow researcher Jeremiah Grossman, first revealed the dangers of clickjacking, says Twitter isn&#8217;t as attractive a clickjacking target as other vectors, however. &#8220;I don&#8217;t see it as all that interesting as an attack point compared to routers, banks, Webmail, etc.,&#8221; says Hansen, founder of SecTheory. &#8220;But I can see why there&#8217;s a fascination in making people say things they didn&#8217;t intend to say.&#8221; </p></blockquote>


<p>Related posts:<ol><li><a href='http://tweeterism.com/how-to-add-a-retweet-button-to-the-twitter-web-interface/' rel='bookmark' title='Permanent Link: How to Add a Retweet Button to the Twitter Web Interface'>How to Add a Retweet Button to the Twitter Web Interface</a></li>
<li><a href='http://tweeterism.com/creating-a-twitter-feed-for-conferences-and-events/' rel='bookmark' title='Permanent Link: Creating a Twitter Feed for Conferences and Events'>Creating a Twitter Feed for Conferences and Events</a></li>
<li><a href='http://tweeterism.com/twitter-magnets-create-poetry-and-share-it-on-twitter/' rel='bookmark' title='Permanent Link: Twitter Magnets: Create Poetry and Share it on Twitter!'>Twitter Magnets: Create Poetry and Share it on Twitter!</a></li>
<li><a href='http://tweeterism.com/combining-twitter-with-your-house-security-system/' rel='bookmark' title='Permanent Link: Combining Twitter With Your House Security System'>Combining Twitter With Your House Security System</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://tweeterism.com/dangerous-clickjacking-hack-for-twitter-revealed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
