+ Reply to Thread
Results 1 to 4 of 4

Thread: Trackers compromised security and Twitter

  1. #1
    Vation's Avatar
    Join Date
    09.01.10
    Location
    uncertain
    P2P Client
    several
    Posts
    565
    Activity Longevity
    1/20 17/20
    Today Posts
    0/5 ssssss565

    Trackers compromised security and Twitter

    Most of us have accounts on several trackers. Many of us use the same email for more than one tracker. Some even use the same passwords for several sites/accounts/services and usernames.

    A result using life password and same user names will provide you:
    loss of your email accounts
    loss trackers accounts
    also loss precious and most valuable Twitter account.

    There were also redirects and bad scripts involved.(be sure that you got up to date PC security and browser)

    Twitter informs on it's site how bad there is and that multiple sites are involved.

    Torrent sites aren’t exactly “new”; however, this is one of the first times that we’ve seen an attack that came from this vector. It appears that for a number of years, a person has been creating torrent sites that require a login and password as well as creating forums set up for torrent site usage and then selling these purportedly well-crafted sites and forums to other people innocently looking to start a download site of their very own. However, these sites came with a little extra — security exploits and backdoors throughout the system. This person then waited for the forums and sites to get popular and then used those exploits to get access to the username, email address, and password of every person who had signed up. Additional exploits to gain admin root on forums that weren’t created by this person also appear to have been utilized; in some instances, the exploit involved redirecting attempts to access the forums to another site that would request log-in information. This information was then used to attempt to gain access to third party sites like Twitter. We haven’t identified all of the forums involved (nor is it likely that we’ll be able to, since we don’t have any connection with them), but as a general rule, if you’ve signed up for a torrent forum or torrent site built by a third party, you should probably change your password there.
    Conclusion Armageddon is coming at least according to Twitter(looks like viral advert but let say there is great menace)

    Among security mortal sins life password and using same nicks are the worse, blamed are usually all other factors...

    sources:
    Twitter Status - Reason #4132 for Changing Your Password

    Torrent Sites Blamed For Twitter Attack | TorrentFreak

    FILEnetworks Blog: What’s The Torrent Site Exploit Twitter Is Talking About?
    Reply With QuoteReply With Quote
    Thanks

  2. Who Said Thanks:

    Blocker (05.02.10)

  3. #2
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,512
    Activity Longevity
    12/20 19/20
    Today Posts
    3/5 ssss39512
    Some even use the same passwords for several sites/accounts/services and usernames.
    Not me, I use completely different details for every site and keep them encrypted in a KeePass database. Also, there are multiple backups of the database all over my house in the form of flashdrives and MicroSD cards. It's the best if you don't want to lose your accounts.
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  4. #3
    Vation's Avatar
    Join Date
    09.01.10
    Location
    uncertain
    P2P Client
    several
    Posts
    565
    Activity Longevity
    1/20 17/20
    Today Posts
    0/5 ssssss565
    @anon hmm you made some mods with hex ed and olly probably use shark to test tracker and peer communication, yes most probably life password person


    It is about average guys. I am always impressed by peoples stupidity. Life password is in these times common. One database leaks and wow suddenly person looses several accounts on several sites. To blame there are always bad hackers with unbelievably high skills.
    Last edited by Vation; 03.02.10 at 20:59.
    Reply With QuoteReply With Quote
    Thanks

  5. #4
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,512
    Activity Longevity
    12/20 19/20
    Today Posts
    3/5 ssss39512
    Quote Originally Posted by Vation View Post
    @anon hmm you made some mods with hex ed and olly probably use shark to test tracker and peer communication, yes most probably life password person
    I didn't use OllyDBG. HxD and smsniff is all you need.
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •