Feeds

Password guessing attack exposed in Twitter pwn

The pursuit of 'happiness'

Website security in corporate America

Miscreants broke into Twitter's admin system on Sunday night using a simple password guessing hack, it has emerged.

A teenage hacker, known in the digital underground as GMZ, claims he obtained access to the micro-blogging site’s admin controls using a brute force dictionary attack. After guessing the login identity of an administrator, in part based on the large number of people she followed, GMZ ran an automated password guessing program overnight to reveal that 'Crystal' used the eminently guessable password of "happiness". The 18-year-old student then used these details to offer up access to Twitter accounts on request through Digital Gangster, an underground hacker forum, Wired reports.

The move enabled griefers to break into the Twitter feeds of the likes of Britney Spears, Fox News and US President-Elect Barack Obama on Monday to push out bogus messages. GMZ sat on the sidelines during this attack because he had failed to use a proxy during his password cracking attack, making him more at risk of identification.

The man behind the mischief offered a instant message interview with Wired after other hackers implicated him in the attack. GMZ backed up the story that he broke into Twitter's admin system by offering a video of the initial attack, which has since been published on YouTube.

The attack itself was made easy not just because of the use of a weak password on a key account, but because Twitter failed to implement the kind of password-guessing hurdles that are commonplace elsewhere on the net - even in far less sensitive environments such as Gmail and Hotmail logins - so that multiple unchallenged log-in attempts were possible. Access to the compromised admin account allowed the login credentials of other accounts to be reset.

"Twitter and other websites should be able to tell when hackers are trying to brute-force their way past a password," said Graham Cluley, senior technology consultant at Sophos. "GMZ says he ran his automatic password guessing program overnight before it finally broke its way in.

"There’s no reason why Twitter couldn’t, say, notice that someone has entered the wrong password three times in a row, and then insist they wait 15 minutes before trying to log in again.

"Twitter could help avoid this problem by insisting that passwords are not known dictionary words, or forcing the use of numbers and other characters - such as underlines, exclamation marks and percentages - in users' chosen passwords."

Twitter co-founder Biz Stone confirmed a dictionary attack was used to gain access to an administrative account but declined to answer further questions, including queries about the duration of the breach.

GMZ, who reports he's been hacking for around three years, has previously claimed responsibility for breaking into the YouTube account of teen actress Miley Cyrus. The latest attack on Twitter reportedly used the same attack script. ®

Protecting users from Firesheep and other Sidejacking attacks with SSL

More from The Register

next story
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Critical Adobe Reader and Acrobat patches FINALLY make it out
Eight vulns healed, including XSS and DoS paths
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Blood-crazed Microsoft axes Trustworthy Computing Group
Security be not a dirty word, me Satya. But crevice, bigod...
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.