Hacker: I broke into Twitter

1 comment | 10I like it!
April 30, 2009, 03:14 PM —  IDG News Service — 

For the second time this year, a hacker has gained administrative access to a Twitter employee's account.

On Wednesday, an anonymous hacker going by the name of Hacker Croll posted 13 screenshots to a French online discussion forum, apparently captured while logged into the Twitter account of Jason Goldman, a director of product management with Twitter.

Twitter cofounder Biz Stone confirmed the breach in a blog post Thursday afternoon. "This week, unauthorized access to Twitter was gained by an outside party," he wrote. "Our initial security reviews and investigations indicate that no account information was altered or removed in any way. However, we discovered that 10 individual accounts were viewed during this unauthorized access."

According to the screenshots, Hacker Croll was able to access account information belonging to high-profile Twitter users such as Britney Spears and Ashton Kutcher. He could also do things such as add or remove featured users, who are suggested to new Twitter members when they sign up.

The hacker may have been able to access information such as e-mail addresses, mobile-phone numbers and a list of the accounts blocked by these users, Stone wrote. "We have personally contacted Twitter users whose accounts were compromised via this unauthorized access," he said.

Hacker Croll claimed to have accessed Goldman's Twitter password by first gaining access to his Yahoo account. "One of the admins has a yahoo account, i've reset the password by answering to the secret question. Then, in the mailbox, i have found her [sic] twitter password," Hacker Croll said Wednesday in a posting to an online discussion forum. "I've used social engineering only, no exploit, no xss vulnerability, no backdoor, np sql injection."

On Monday, Goldman sent a Twitter message saying that his Yahoo mail account had been hacked.

Twitter has had a rash of security problems this year.

In January, another hacker going by the name of GMZ said he was able to gain access to an administrative account by guessing the password of a Twitter support staffer, according to a Wired report. The password was reportedly an easy-to-guess word: happiness.

Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world

I like it!
Close

On Twitter now

twitter

Powered by Twitter
You are logged in | Sign out
Sign in and post to Twitter

What are you thinking?

Cancel Tweet sent

On Twitter now

Comments

This leaves two questions

When is Yahoo going to get rid of the stock security questions? This is not the first time someone has hacked a Yahoo Mail account.

Two why was someone with such high security access using something as unsecure as Yahoo Mail?
| reply
peer-to-peer

Esther Schindler
If the comments are ugly, the code is ugly

claird
SVG a graphics format for 21st century

pasmith
Take Chrome OS for a test spin

Sandra Henry-Stocker
Solaris Tip: Have Your Files Changed Since Installation?

sjvn
64-bits of protection?

jfruh
Android fragments vs. the iPhone monolith

mikelgan
What Gizmodo missed about the Pro WX Wireless USB disk drive

 

Where Google Chrome security fails: the password
I heard mention that the Chrome OS will have some sort of encryption available a la bitlocker. If it's possible to encrypt personal data using another password or key, then it may have potential for very secure data.... And Ubuntu has an 'encrypt home directory' option, perhaps google should follow suit.
- Dann

Join the conversation here

The Daily Tip

The Daily TipQuick, practical advice for IT pros. Made fresh daily.

Hot tips:

Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.

Newsletters

Subscribe to ITWORLD TODAY and receive the latest IT news and analysis.

I would like to receive offers via email from ITworld partners.
By clicking submit you agree to the terms and conditions outlined in ITworld's privacy policy.
Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace