• On CBSSports.com: March Madness® on Demand
February 3, 2010 6:39 AM PST

Twitter reveals torrent scam details

by Lance Whitney
  • Font size
  • Print
  • 1 comment

Twitter has revealed the back story on why it reset passwords this week for many of its users.

The phishing attacks that forced Twitter to change account passwords stemmed from discovery of a scam being run by a torrent Web site creator, explained Del Harvey, Twitter's director of trust and safety, in a blog post Tuesday evening.

Twitter had found that someone for the past few years had been building torrent sites and forums requiring a log-in and password. This person then sold these Web sites and forums to people interested in starting their own torrent download sites.

Unknown to the buyers, these sites actually contained security holes that allowed the cybercrook to gain access to the buyers' log-in information for sites like Twitter. This was done by grabbing log-in attempts to the forums and redirecting them to third-party Web sites where the criminals could capture a user's credentials.

"These sites came with a little extra--security exploits and backdoors throughout the system," Harvey said. "This person then waited for the forums and sites to get popular and then used those exploits to get access to the username, email address, and password of every person who had signed up."

A red flag was first raised on Twitter's end when it noticed an abnormally high number of followers for certain accounts. This prompted the company to investigate and eventually reset the passwords for anyone following those suspicious accounts. Twitter noted that although torrent sites have been around a while, this is the first time it's seen an attack using this angle.

"While not all users who were sent a password reset request fall into this category, we felt that it was important to put this knowledge out there so that users would know of the possibility of compromise of their data by a third party unrelated to their Twitter account," Harvey said.

Twitter advises people who have signed up for third-party torrent accounts to change their passwords at those sites and to refrain from using the same password at multiple sites. More tips on safe tweeting can be found on Twitter's help pages.

Lance Whitney wears a few different technology hats--journalist, Web developer, and software trainer. He's a contributing editor for Microsoft TechNet Magazine and writes for other computer publications and Web sites. You can follow Lance on Twitter at @lancewhit. Lance is a member of the CNET Blog Network, and he is not an employee of CNET.
Recent posts from Security
Ex-employee accused of remotely disabling 100 cars
Beware the new Facebook password reset scam
Malware found on second Vodafone HTC Magic
Microsoft says it decimated Waledac botnet
Virtual PC hole could lead to attacks, security firm says
SEC: Stocks boosted via hijacked accounts
Breaking the Mariposa botnet (Q&A)
Internet safety video could win you $10,000
Add a Comment (Log in or register)
by dumbspammers February 3, 2010 1:12 PM PST
My money is on the RIAA or MPAA being the backers of the guy selling the "torrent sites.."
Reply to this comment 2 people like this comment
advertisement
Click Here
CNET River
  • image
    GreeterDan: enjoyed spending time at #sxsw with @rachelannyes @andrewhyde @actiongrl @mariangoodell @epiphany23 @julzie and others!
    by Daniel Terdiman
  • image
    GreeterDan: Random 43 minutes during SXSWi 1,500 #sxsw tweets. Random 43 mins during SXSW Music: 555 tweets. Proving? We tweet more! FTW! ;-)
    by Daniel Terdiman
  • image
    mollywood: Frankly don't know what I'm madder about today. ACTA or the Droid 2.1 delay. I hate to say it, but leaning toward 2.1 delay. ETA TBD!?!?
    by Molly Wood
  • image
    caro: One more cup of chamomile tea with lemon and then I'm going to sleep. Long day tomorrow. Hoping the SXSW plague has been swiftly defeated.
    by Caroline McCarthy
  • image
advertisement

Viacom, Google air dirty laundry in court docs

Copyright confrontation gets fierce. Viacom says YouTube founders always intended to build video version of Napster and looked for ways to "to avoid the copyright bastards."
• Google's statement on YouTube-Viacom

Google's fast pipe to Asia almost ready

An undersea cable built by a group including Google and telecom companies is set to start carrying traffic at any point, with Google to get as much as 20 percent of the capacity.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right