iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Twitterers Spooked By Clickjacking
Search:
[ insider_reports_insider ]

Twitterers Spooked By Clickjacking



SecurityProNews
Staff Writer
2009-02-13

SecurityProNews: Insider Reports Insider Reports RSS Feed


Seems like popular websites go through stages: early buzz and adoption, mainstream media recognition, funding and monetization brainstorming, meteoric growth, the how-easy-is-it-to-hack stage, the marketer gaming stage, the juggernaut stage, and finally, the full corporate-government conspiracy stage. Twitter, it would appear, is in the how-easy-is-it-to-hack stage.

Don't Click The Twitter Link
Don't Click The Twitter Link
2009 has already been a rough year for Twitter in terms of hacker exploits. Yesterday, lots of Twitterers were clickjacked. The most basic explanation of clickjacking is when a user is fooled into clicking a link via embedded code or script loading a site into an iframe and offering a clickable phony link to someplace awful. Often it's used to get log in or financial information.

In Twitter's case, it almost seems like a test run to freak a lot of people out. Some users saw the words "Don't Click:" followed by a link. Either because that particular phrase has the same reverse power as its cousins Don't Look, Don't Fall, and Don't Drop It, or because they thought their friends on Twitter were messing them, many people clicked the link they were told not to click.

The result? The message and link posted to that person's account and followers, perpetuating a very annoying cycle and causing users to have mild I've-been-hacked freakouts.

Twitter founder Biz Stone acknowledged the incident on his blog and said the Twitter crew had updated the site to block the clickjacking technique.

For those worried about clickjacking when not on Twitter, Graham Clulely at Sophos recommends FireFox's NoScript plug-in, which posted a warning about the attempt the first time.



About the Author:
SecurityProNews is a daily online and email publication focusing on internet security issues.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds