Hackers Infect Twitterverse With Worm Using Old, Known Bug

80beatsBy Jennifer WelshSep 22, 2010 9:31 PM


Sign up for our email newsletter for the latest science news

Yesterday's Twitter meltdown was caused by a known flaw that resurfaced with the help of a 17-year-old Australian and a Scandinavian developer, among others. The boy, Pearce Delphin, and the developer, Magnus Holm, discovered the JavaScript vulnerability, which allowed hackers to make other users launch various functions merely by mousing over links in tweets sent by the hackers. Instead of reporting the vulnerability to Twitter, Delphin tweeted it--and it caught on.

"I did it merely to see if it could be done ... that JavaScript really could be executed within a tweet," Delphin told AFP via email. "At the time of posting the tweet, I had no idea it was going to take off how it did. I just hadn't even considered it." [AFP]

Holm takes the credit for turning the vulnerability into a worm, by making it re-tweet itself, that propagated virally among users.

At first he thought the worm wouldn't really do anything: "meh, this worm doesn't really scale. the users can just delete the tweet :(" he wrote. Then within a few minutes he saw that it had started spreading virally. "holy shit. I think this is exponential: "3381 more results since you started searching," he said - adding, a few minutes later "This is scary." [The Guardian]

Many hackers got on the bandwagon, adapting the script so that anyone who moused over it automatically tweeted a bizarre message, or opened a pornographic website, covered the page in huge letters, or turned the whole page into a link that re-tweeted the worm. The interesting twist is that the vulnerability was previously reported to Twitter by Japanese developer Masato Kinugawa

on August 14 and the site then promptly fixed. But a site update (which Twitter says

is unrelated to the "new Twitter" launch and roll-outs) reversed the patch, making this script hackable again. Kinugawa even made a "Rainbow Twtr" account, now defunct, showing how the vulnerability could allowed him to change the color of his tweets. The hack affected thousands of Twitter users, including the White House's press secretary Robert Gibbs

, who switched to using TweetDeck, as users of third-party applications weren't affected by the bug. Related content: Discoblog: How To Make Your Twitter Followers Uneasy: Use ShadyURLs

Discoblog: It Has 3,700 Facebook Friends, 1,800 Twitter Followers, & It’s a Tree

80beats: Twitter’s New @anywhere Aims to Make the Web One Big, Tweeting Coop


Twitter's Greatest Hits—and Greatest Misses

Image: Flickr/Monkeyworks illustration

1 free article left
Want More? Get unlimited access for as low as $1.99/month

Already a subscriber?

Register or Log In

1 free articleSubscribe
Discover Magazine Logo
Want more?

Keep reading for as low as $1.99!


Already a subscriber?

Register or Log In

More From Discover
Recommendations From Our Store
Shop Now
Stay Curious
Our List

Sign up for our weekly science updates.

To The Magazine

Save up to 40% off the cover price when you subscribe to Discover magazine.

Copyright © 2023 Kalmbach Media Co.