meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, March 16th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 16 March 2017

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. thecounter twitter hack; Telegram/WhatsApp Vulnerability

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, March 16th, 2017 edition of the Sanct Center Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.6

A large number of Twitter accounts did post pro-Turkey messages this morning, apparently due to a compromise of the Twitter app Twitter counter.

0:24.5

Twitter counter can be used to create statistics for specific Twitter users, but of course in order

0:30.9

to create these statistics, Twitter counter will ask you for access to your account.

0:37.4

Now, Twitter counter uses OAuth in order to accomplish that, which is of course the standard

0:42.8

for Twitter, which actually sort of helped a little bit in this case.

0:47.1

Apparently, what happened was that someone figured out to use these privileges that

0:53.9

Twitter counter had with its customers to then send

0:58.7

tweets. Now, once this became obvious, Twitter counter was able to revoke its API key,

1:06.0

which of course did remove access to the attacker. Another advantage of Oath, of course, is that this particular compromise did not affect users'

1:18.6

Twitter passwords themselves, just the credentials they did negotiate with Twitter counter.

1:25.6

Now the service is down at this point, not really sure when it will be up again.

1:32.3

I guess they first have to figure out what exactly happened and how to fix it.

1:38.3

But lesson learned here for anybody using a social network and using O-O-O-OF.

1:44.7

It is important that occasionally you do review the applications that do have access to your account.

1:51.9

And of course, if you sign up with a particular application, make sure you don't give it access

1:59.3

beyond what it needs to do its service.

2:02.5

Not really sure why Twitter counter had access to post tweets on the user's behalf

2:08.6

that shouldn't really be necessary in order to just collect statistics.

2:13.5

But I haven't used, luckily, this service in the past.

2:17.3

So I'm not really that familiar with it.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.