Twitter hack grabs director's account

'Hacker Croll' obtains administrative rights

For the second time this year, a hacker has gained administrative access to a Twitter employee's account.

An anonymous hacker going by the name of Hacker Croll posted 13 screenshots to a French online discussion forum, apparently captured while logged into the Twitter account of Jason Goldman, a director of product management with Twitter.

Twitter CEO Biz Stone confirmed the breach in a blog post on Thursday. "This week, unauthorised access to Twitter was gained by an outside party," he wrote. "Our initial security reviews and investigations indicate that no account information was altered or removed in any way. However, we discovered that 10 individual accounts were viewed during this unauthorised access."

According to the screenshots, Hacker Croll was able to access account information belonging to high-profile Twitter users such as Britney Spears and Ashton Kutcher. He could also do things such as add or remove featured users, who are suggested to new Twitter members when they sign up.

The hacker may have been able to access information such as email addresses, mobile-phone numbers and a list of the accounts blocked by these users, Stone wrote. "We have personally contacted Twitter users whose accounts were compromised via this unauthorized access," he said.

Hacker Croll claimed to have accessed Goldman's Twitter password by first gaining access to his Yahoo account. "One of the admins has a yahoo account, i've reset the password by answering to the secret question. Then, in the mailbox, i have found her [sic] twitter password," Hacker Croll said on Wednesday in a posting to an online discussion forum. "I've used social engineering only, no exploit, no xss vulnerability, no backdoor, np sql injection."

On Monday, Goldman sent a Twitter message saying that his Yahoo mail account had been hacked.

Twitter has had a rash of security problems this year.

In January, another hacker going by the name of GMZ said he was able to gain access to an administrative account by guessing the password of a Twitter support staffer, according to a Wired report. The password was reportedly an easy-to-guess word: happiness.

GMZ then used that access to take control of 33 high-profile accounts, including those for Spears, US President Barack Obama and Fox News.

Twitter has also been hit with several fast-spreading worm attacks this year that preyed on web programming flaws on the site.

Although Stone promised a "full security review of all access points to Twitter" after the January incident, the site's security is "very weak", according to Manuel Dorne, the French blogger and IT project manager who first published news of the most recent Twitter hack.

Stone made a similar promise this time around too. "Twitter takes security very seriously so we will be conducting a thorough, independent security audit of all internal systems and implementing additional anti-intrusion measures to further safeguard user data," he wrote on Thursday.

Anyone who tries to log into admin.twitter.com is given a login prompt, and since Twitter user names are already public, attackers have only to guess the password. That could have been what happened with Goldman's account, Dorne said. "Maybe the password was the name of his child or of his wife and the hacker knew it."

These types of attacks, called social engineering attacks by researchers, are effective and commonplace. Last year, a hacker used the same technique described by Hacker Croll to gain access to the Yahoo email account of vice-presidential candidate Sarah Palin.

"We have to be careful and not underestimate social engineering attacks," said Lance James, co-founder of consulting firm Secure Science. "If they work for stealing money from banks, it's going to be trivial to hijack social networks such as Twitter."



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

Legal risks of uncontrolled email and web use

Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.

The challenge of strategic alignment

Recent research also shows that many organisations give too much prominence to internally generated KPIs – controlling the controllable – rather than looking outwards at threats and opportunities on the horizon which can ultimately be far more influential on performance.

Six essential steps to successful IT centralisation

This report, based on the real experience of a recent centralisation project, is aimed at those involved in IT strategy within their organisation. It provides some practical insights for CIOs, CTOs, Heads of IT, IT Directors and those involved more closely with the service management function.

Managing email: Exploring common email management challenges (and how to overcome them)

We surveyed 157 IT professionals to understand the difficulties and opportunities faced by email managers. From this we were able to highlight some easy-to-manange solutions to their most pressing problems.


CIO UK - Business - Technology - Leadership

Differentiate your company with complete CRM

Focused on productivity and empowerment and leveraging the natural rhythms people work
What defines Complete CRM? How businesses can better engage customers and users, manage customer transactions, and analyse results to adapt and take advantage of changing business and economic circumstances.

DOWNLOAD

Oracle White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One.

CIO are running a short survey to discover how UK businesses are managing internet and email misuse in the Enterprise.

COMPLETE SURVEY

Virtualisation - The 'black hole' of security?

Covering the set of issues, ideas and perceptions discussed during a recently held debate about the effect of virtualisation techniques on organisational security. This paper provides a comprehensive account of all the subject matters debated and concludes with key takeaways and IDC recommended actions.

DOWNLOAD

Trend Micro



* *