Register for an account

X

Enter your name and email address below.

Your email address is used to log in and will not be shared or sold. Read our privacy policy.

X

Website access code

Enter your access code into the form field below.

If you are a Zinio, Nook, Kindle, Apple, or Google Play subscriber, you can enter your website access code to gain subscriber access. Your website access code is located in the upper right corner of the Table of Contents page of your digital edition.

Technology

Hackers Infect Twitterverse With Worm Using Old, Known Bug

twitter.jpg

Newsletter

Sign up for our email newsletter for the latest science news

Yesterday's Twitter meltdown was caused by a known flaw that resurfaced with the help of a 17-year-old Australian and a Scandinavian developer, among others. The boy, Pearce Delphin, and the developer, Magnus Holm, discovered the JavaScript vulnerability, which allowed hackers to make other users launch various functions merely by mousing over links in tweets sent by the hackers. Instead of reporting the vulnerability to Twitter, Delphin tweeted it--and it caught on.

"I did it merely to see if it could be done ... that JavaScript really could be executed within a tweet," Delphin told AFP via email. "At the time of posting the tweet, I had no idea it was going to take off how it did. I just hadn't even considered it." [AFP]

Holm takes the credit for turning the vulnerability into a worm, by making it re-tweet itself, that propagated virally among Twitter.com users.

At first he thought the worm wouldn't really do anything: "meh, this worm doesn't really scale. the users can just delete the tweet :(" he wrote. Then within a few minutes he saw that it had started spreading virally. "holy shit. I think this is exponential: "3381 more results since you started searching," he said - adding, a few minutes later "This is scary." [The Guardian]

Many hackers got on the bandwagon, adapting the script so that anyone who moused over it automatically tweeted a bizarre message, or opened a pornographic website, covered the page in huge letters, or turned the whole page into a link that re-tweeted the worm. The interesting twist is that the vulnerability was previously reported to Twitter by Japanese developer Masato Kinugawa

on August 14 and the site then promptly fixed. But a site update (which Twitter says

is unrelated to the "new Twitter" launch and roll-outs) reversed the patch, making this script hackable again. Kinugawa even made a "Rainbow Twtr" account, now defunct, showing how the vulnerability could allowed him to change the color of his tweets. The hack affected thousands of Twitter users, including the White House's press secretary Robert Gibbs

, who switched to using TweetDeck, as users of third-party applications weren't affected by the bug. Related content: Discoblog: How To Make Your Twitter Followers Uneasy: Use ShadyURLs

Discoblog: It Has 3,700 Facebook Friends, 1,800 Twitter Followers, & It’s a Tree

80beats: Twitter’s New @anywhere Aims to Make the Web One Big, Tweeting Coop

DISCOVER:

Twitter's Greatest Hits—and Greatest Misses

Image: Flickr/Monkeyworks illustration

2 Free Articles Left

Want it all? Get unlimited access when you subscribe.

Subscribe

Already a subscriber? Register or Log In

Want unlimited access?

Subscribe today and save 70%

Subscribe

Already a subscriber? Register or Log In