• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
TheWayoftheWeb

TheWayoftheWeb

Content and Digital Marketing Specialists

  • Blog
  • The Cipher
  • About Us
    • Useful Resources For Businesses In Peterborough, UK
  • Contact Us
  • Show Search
Hide Search

hacking

The aftermath of Twitters biggest phishing scam

March 1, 2010 By Dan Thornton

Over the last week, many people have fallen foul of the latest phishing scam to do the rounds of Twitter. And an unusual number of high profile individuals have been included in the list of users affected, including the Press Complaints Commission, BBC correspondent Nick Higham, the Guardian’s Head of Audio Matt Wells, bank First Direct, and environment minister Ed Milliband.

Environment Minister Ed Milliband caught by phishing scam
Environment Minister Ed Milliband caught by phishing scam

Phishing scams have long been endured by most internet users – the traditional mechanism has been via email, but as social networks have becoming hugely popular, they’ve become the vector of choice. And Twitter is particularly attractive as the speed with which messages can spread is combined with the use of short urls, which help to mask the malevolence of the message.

While this is just another example of the huge amount of phishing attempts which exist, the higher profile of these attacks as they affect prominent politicians will hopefully lead to a better awareness and response by governments.

It’s probably a forlorn hope, but for example, here are some things which might change:

  • More education about phishing and spam to the ‘general public’ – how about a public awareness campaign?
  • More understanding about how normal users can have accounts compromised very easily – for instance, with ‘Three Strikes Rules’.
  • More people using offline backups of any content that is valuable or useful to them
  • More of a move towards data privacy, and Vendor Relationship Management, to allow users to only share the information they choose with any service provider under strict controls.
  • A rethink of the UK Identity Card scheme which includes private businesses taking fingerprint and photos.

Importantly, it should place the risks of Social Engineering alongside those of teenage cyberwarfare specialists taking down defence satellites from their bedroom. If a private company was, for example, storing fingerprint data, you wouldn’t need to target their infrastructure (Although I’m not sure most chemists have a particularly high level of internet security) – you’d use social engineering on their employees via Facebook, Twitter, or offline in person to gain information and access.

Of course, technology can play a part, and I’m sure Twitter will increase their response to phishers in future, particularly as a high profile attack via any platform is never good for PR. But any measures will always be part of a never-ending arms race, and only when every individual is educated enough will there be any noticeable difference…

Big money for hacked Twitter accounts

January 31, 2010 By Dan Thornton

Stolen Twitter accounts appear to be commanding a premium amongst hackers sharing details on forums.

Data stealing software is a risk to your details for any site, but according to Kaspersky researcher Dmitry Bestuzhev, he’s seen  a Twitter account with just 320 followers offered for as much as $1000. In this case, the three-letter username may have influenced the price.

That compares with Gmail accounts for $82, Rapidshare accounts for $5 per month, and other sites including Skype and Facebook. Bestuzhev also went on to say Kaspersky had detected 70,000 data stealing programmes in 2009, which is twice as many as in 2008.

Twitter is likely to be a preferred route to spread malware as links can spread in near real-time to hundreds or thousands of followers – each of whom can quickly and easily repeat a malware message to their own network.

Malware messages are also hidden by shortened urls, and with the amount of links spread via Twitter, there’s a good chance people are less suspicious than seeing the same links in an email or IM message.

It’s a reminder to make sure you use a unique password which is a mix of alphanumeric characters, and to change it regularly. Be careful of sharing it with third party sites and tools which aren’t using Twitter’s OAuth protocol, and be careful with links being posted by others – even including people you trust.

(Via Computerworld)

Has Twitter become a weapon?

August 10, 2009 By Dan Thornton

The recent Distributed Denial of Service (DDoS) attack on popular social networks was mainly felt by Twitter, which seemed to either be more susceptible or hit harder by the action, resulting in it going offline entirely for a short period.

The concept of Governments using the internet for spreading information or cyberwarfare is not a new one – but the question is how prevalent it is becoming on social networks, and how many users are aware of it happening?

Twitter seems the most likely place for this question to play out – combine a design which lends itself to the fast spread of information, and an average user age which is more likely, as a percentage of users, to be interested in news and events (particularly political), than most social networks.

Examples of the fast spread of news are commonplace, particularly when it comes to natural disasters, such as earthquakes, or human disasters, such as terrorism or fire. And increasingly these pieces of breaking information are being repeated and picked up by unquestioning users seeking to capitalise on the interest, major news organisations, and even shops using it for spam purposes.

Usage of the media by both Governments and unofficial organisations has long existed, but the internet removes the need to engage with ‘official’ media sources to reach a large audience.

And now we’re seeing the potential for Governments or organisations to co-ordinate attacks against popular services. That’s something that print distribution has somewhat protected us against – you might be able to control or attack a printing press in your own country, but it’s harder to exert pressure on foreign media platforms (although not impossible).

But the internet is accessible from any location, meaning that those who don’t believe in freedom of speech or information are able to co-ordinate their attacks on whichever target they deem suitable – and when it comes to media and social networks, we’re relying on the efforts of private companies to respond. And whilst, for example, the UK Government might interject as best it could to preserve a media institution such as the BBC for the good of the country (being a mechanism to effectively reach the population in times of emergency), do we expect – or indeed do we want, Governments to be increasingly involved in attempts to protect social networks and microblogging?

 

What do you think?

Want evidence of end user control?

April 3, 2009 By Dan Thornton

If you really want to underline the way control is now being shared with an ever greater number of people historically know as your ‘audience’, then show people the increasing rise of Firefox browser usage – then show them Greasemonkey.

Now Firefox isn’t the most used browser globally – Internet Explorer still rules, and Google’s Chrome certainly has some advantages and enthusiastic adopters. But whether or not Firefox ever dominates the browser market, the influence of the open source approach, add-ons and plug-ins is undeniable. It’s the reason that many people, including myself, might use Chrome for certain tasks for speed, but can’t give up the utility of plugins which offer everything from easy ways to see the way a page is coded, to Swedish spellchecking, mouse gestures and more.

But why is Greasemonkey so incredibly important?

Greasemonkey is a Mozilla Firefox add-on that allows users to install scripts on-the-fly changes to most HTML-based web pages. As Greasemonkey scripts are persistent, the changes made to the web pages are executed every time the page is opened, making them effectively permanent for the user running the script. Greasemonkey can be used for adding new functions to web pages (for example, embedding price comparison in Amazon.com web pages), fixing rendering bugs, combining data from multiple webpages, and numerous other purposes. From Wikipedia.

So that means:

You can spend as much time and money as you like on designing your webpage, but if I want to disable elements, change the layout, or do whatever I like, I can.

For instance, Facebook’s redesign angered many people – so if you want to hide the Highlights sidebar, just install one of three Greasemonkey options.

Or you can just emulate the old Facebook design.

And what’s really interesing?

As a website owner/publisher, I’m not aware of any way you’d know this was happening via analytics (And I’ve asked a few metrics/analytics types before posting), and you wouldn’t know what users are adding to your site to improve their experience, and possibly conversion rates.

(If you do know ways to track any of that information automatically, I’d love you to share it in the comments.)

Your users would though.

Resources:

You can keep up with the Greasemonkey blog at Greasespot, and find Userscripts for it at Userscripts.org. Please do keep in mind that you’re installing code which may in a very small amount of cases have been created by people who aren’t 100% lovely, so do some research before adding new scripts. Or just don’t blame this post if you kill the internet by accident.

  • « Go to Previous Page
  • Page 1
  • Page 2

Primary Sidebar

Join us…

  • Facebook
  • Instagram
  • LinkedIn
  • RSS
  • Twitter

We only exist to deliver results for your business. So you get fresh Content, expert SEO, engaging Social Media, or a new Website which is right for you – and your customers.

We help you build your brand, reach more customers and increase your revenue

Search

Categories

Creative Commons License
This work by TheWayoftheWeb is provided under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

Start growing your business today Contact Us

TheWayoftheWeb

Copyright © 2026· TheWayoftheWeb Ltd. Company Number 08038527. ICO registration: ZB397650