Feeds

Bloke leaks '1000s' of Twitter login tokens, says he can hack ANY twit

Known vulnerability sat on by Twitter, inevitable happens

Build a business case: developing custom apps

A hacker calling himself the "Mauritania Attacker" claims he has compromised every Twitter user account on the planet - and leaked the OAuth tokens for thousands of Turkish tweeters.

Meanwhile, a security researcher claims to have obtained similar details by creating a fake app that masqueraded as Twitter's own third-party client, Tweetdeck.

The Mauritania Attacker's token dump reveals OAuth data rather than passwords. The miscreant boasted to Indian security site Techworm that he had access to the "entire database of users on Twitter" and that "no account is safe".

The attacker has leaked more than 15,000 account details onto file-sharing service Zippyshare. He also claims to have the “oauth_token secret codes” which, he says, will allow him to log directly into victims' accounts.

On cursory inspection, at least, the authentication tokens look genuine. The circumstances of the hack suggest that leak stems from a hacked third-party app rather than Twitter itself.

Matters would be a lot worse if actual passwords were leaked, in which case Twitter would be obliged to reset passwords to avoid account hijacking on a grand scale. As things stand, it might still be a good idea to reset access to connected third-party apps.

"The details, which appear to be genuine, do not include passwords," writes David Meyer on tech analysis blog GigaOM. "They do include OAuth tokens, though, so Twitter users should probably revoke and re-establish access to connected third-party apps."

'Twitter's implementation of OAuth2 is vulnerable many weeks ago'

OAuth tokens that are used to connect Twitter accounts to third-party services without obliging users to hand over passwords. Issues with the technology are not uncommon. For example, security researcher Kelker Ryan warned Twitter's implementation of OAuth2 is vulnerable many weeks ago.

He was unable to get a response from Twitter and The Register passed his research to representatives of the micro-blogging firm with a request to bring it to the attention of techies two weeks ago.

We've yet to hear back from Twitter, but the latest claims of a hack ought to ought to be enough to prompt a deeper investigation into the issue in general. It's unclear whether or not Mauritania Attacker exploited the vulnerability discovered by Ryan, though the security researcher suspects that this is at least possible.

"I don't know anything about that in terms of the person who did it, but I imagine that my post gave a few people some ideas and they took advantage of the Twitter vuln by using APIs to request information from accounts without needing any user interaction," Ryan told El Reg. "I would have to play around a bit to see if it's possible, but I don't see why it wouldn't be."

"The vuln that I wrote about on coderwall.com allows for anyone's application to trick the Twitter service into thinking that the application request are authentically coming from the TweetDeck application," he added.

A more detailed explanation of a compromised OAuth consumer secret uncovered by Ryan can be found on Stack Overflow.

However Mikko H. Hypponen, chief research officer at F-Secure, said that based on the leaked credentials the attack is probably the result of a phishing attack targeting Turkey. "My guess: it's some phishing attack on a Turkish site," Hypponen told El Reg. "Look how many of the accounts they list have a reference to Turkey. Even the ones which don't have an obvious link to Turkey in name seem to be from Turkey."

We passed on claims of a hack against OAuth tokens to Twitter but are yet to hear back. We'll update this story as and when we hear more.

Mauritania Attacker founded a hacktivist collective called AnonGhost, which has so far specialised in hacking and defacing the websites of US and British firms and the oil industry, GigaOM adds. ®

Endpoint data privacy in the cloud is easier than you think

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
iWallet: No BONKING PLEASE, we're Apple
BLE-ding iPhones, not NFC bonkers, will drive trend - marketeers
Multipath TCP speeds up the internet so much that security breaks
Black Hat research says proposed protocol will bork network probes, flummox firewalls
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
They're not emails, they're business records, says court
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?