Frauds and Ends
  • Our Solutions
  • Customers
  • Partners
  • News & Events
  • Blog
    • Latest Blog Posts
    • About the Authors
    • Subscribe to Blog via Email
  • Company
  • Resource Center



January 9, 2009

Social Networking Abuse – Twitter Hack on Youtube

The embed video below shows teenage hacker CMZ walking through his attack on Twitter using a brute force password attack. CMZ exploited the fact that Twitter did not put time-outs on login attempts by running a series of dictionary attacks against the admins account to correctly determine the password as ‘Happiness’. The admin’s details were posted on digitalgangster, which were then used to send spam through Barack Obama and Britney Spears accounts.

This kind of brute force attack using a guessed user name and password generator by a teenager should send chills down any company that thinks that a user name and password is sufficient to keep their crown jewels safe.

Device Intelligence and Device Identification can’t fix bad admin security practice but many social networks are now turning to the device as a form of transparent two-factor authentication to determine whether an account is being accessed from an unauthorized computer, or to detect when the same computer is accessing multiple unrelated accounts.

  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  

Posted by Alisdair Faulkner Categories: Account Compromise. Device Identification. Social Networks. Web Application Security

Leave a Comment

Click here to cancel reply.

  • < Previous Article
  • Translator

  • Subscribe

    Subscribe Via Email
    Subscribe to our RSS Feed
    Follow us on Twitter
  • Top Posts

    • Casual Disconnect: Fraudsters Take Fun & Profit Out Of Social Games
    • Catch Me If You Can – Mining Data to Spot Cybercrime Patterns
    • Boys Will Be Boys—And Fraudsters
    • IRCE 2010 Report: What Internet Retailers Really Want for Christmas This Year
    • Marketing & Fraud Detection: Friction or Faction?
  • Additional Resources

    Ponemon Study Ponemon Study:
    Consumer Attitudes on
    Privacy & Fraud Prevention

    download now

    Executive Primer Executive Primer:
    Using Device ID for
    Fraud Prevention

    download now

    Free White Paper Technical White Paper:
    Device Intelligence In-depth

    download now

  • Categories

  • Blog Archives

ThreatMetrix Comics

threatmetrix comics

Episode 10: Global Money Transfer Scam Caught, Find out how ThreatMetrix thwarts Gromyko's money transfer scam plans

View this episode and more >

Blogroll

  • Dark Reading
  • Inside Social Games
  • Javelin Strategy
  • Online Personals Watch
  • Scam Detectives Blog
  • Shop.org
  • The Fraud Blog
  • Virtual Goods

Join Us

  • Twitter
  • Facebook
  • SlideShare
  • LinkedIn
  • Vimeo
  • YouTube
  • News RSS Feed

Become Our Customer | Contact Support | Schedule a Demo | Call us at 1.650.625.1451
© 2010 Threatmetrix All Rights Reserved. Privacy Policy | Site Map | Terms of Service