Twitter application Grader.com hacked

By Robert McMillan, IDG News Service |  Security Add a new comment

A popular Twitter application used to measure the influence of Twitter users has been hacked and used to send spam messages.

Hackers broke into the Grader.com Twitter application Thursday and used it to spam the Twitter pages of people who enabled the service. Grader users found themselves sending a Twitter message that read "Biz Stone Promoting Twitter in 2006" and contained a link to a newly registered Web domain that hosted a video of Twitter co-founder Biz Stone.

The hackers appear to be trying to improve the search engine ranking of the domain Seonix.org, an online money-making site, which was registered on Thursday, said Rik Ferguson, a security researcher with Trend Micro who blogged about the incident.

Grader.com is a Twitter add-on that lets users measure how influential they are on the social media network.

The founder of Grader.com's parent company, HubSpot, said his company was blocking the unauthorized messages, but he could not say how the compromise occurred.

"All indications are that security on one of the Grader.com applications (Twitter Grader) was compromised," said Dharmesh Shah in an e-mail message. "As a result, an unauthorized third-party was able to post tweets on behalf of some of our users."

"We have updated the system to not allow unauthorized tweets to be sent out anymore, and are working furiously to research the issue further and make changes such that it doesn't happen again," he said. "Security issues are never fun and we hate that this happened. Our apologies to all of our users and those that have trusted us." The issue was "totally our fault," he added.

Shah's own Twitter account sent the Biz Stone spam message, as did the account used by Grader.com.

Twitter users caught a break this time because the Seonix.org Web site is not malicious, according to Ferguson. If they had wanted to, the hackers could have tried to install unauthorized software such as a Trojan horse program on the machines of anyone who clicked on the Seonix.org link.

It's not clear how many people use the Grader.com service, but the company's Twitter account is followed by more than 50,000 people.

The hack shows why hackers are increasingly interested in social media and the applications that work on sites such as Twitter and Facebook. "If you can pick an app that has a lot of users and find a way in, then it's a real big bang for the buck," Ferguson said.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question