|
|
|
Spammers Bypass Twitter s URL Restrictions in Direct Messages |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Présentation : Following media reports that Twitter has restricted URLs in direct messages, spammers found a way around this restriction this weekend in order to push diet pill spam links. Fig1_5.png Figure 1. A direct message sends users to the tweet containing the spam link We first noticed this when someone we follow on Twitter, who has never followed us before, started following us. Shortly after receiving the notification that we had a new follower, we received a direct message from the user. Fig2_3.png Figure 2. A malicious link sent to a Twitter user through direct message Unlike the usual Twitter spam, the link found in the message had directed us back to Twitter. It was a link specifically to a tweet, which the user had posted on their account. The link found within the tweet, led to a common type of diet pill spam, which had been found on various social networks over the years. Fig3_3.png Figure 3. Clicking on the links directs users to a diet spam Web page By searching for the keywords I recommend site on Twitter, we found hundreds of Twitter users who tweeted similar links. This means their accounts had also been compromised and many of their followers received direct messages similar to ours. Fig4_1.png Figure 4. Users tweets containing diet pill spam links Upon further investigation, we discovered that Twitter is currently blocking links to URL shortening services, such as bit.ly and TinyURL. When we attempted to send the links from these services to friends through a direct message, we received an error message. Fig5_1.png Figure 5. Twitter support article notes changes being made to direct messages Twitter may be blocking these links in direct messages because spammers typically mask their spam domain links through these shortening services. A note found on a Twitter help center article states that back-end restructuring efforts may prevent some URLs from being sent. Despite this issue, spammers have found a workaround to continue their efforts. If you or someone you know sent out a spam link through a tweet or direct message, Symantec recommends that you follow these steps to ensure that your account is no longer compromised.
Les mots clés de la revue de presse pour cet article : bypass twitter Les videos sur SecuObs pour les mots clés : bypass twitter Les éléments de la revue Twitter pour les mots clé : bypass
Les derniers articles du site "Symantec Connect Security Response Billets" :
- What you need to know about election apps and your personal data - Microsoft Patch Tuesday April 2016 - New Adobe Flash Player exploit used by Magnitude and Nuclear exploit kits - Latest Intelligence for March 2016 - New Flash zero-day exploited by attackers in the wild - Samsam may signal a new trend of targeted ransomware - Four tax scams to watch out for this tax season - Most prevalent Android ransomware in the West arrives in Japan - Taiwan targeted with new cyberespionage back door Trojan - Seven Iranians charged in relation to cyberattacks against US
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.190.17.190 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.190.17.190 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|