Author |
Message |
Linux_User
I haven't seen my friends in so long
Joined: Tue May 05, 2009 3:29 pm Posts: 7173
|
Just received this direct message from Oceanicitl on Twitter. It looks like a scam. Has her account been hacked?
|
Sat Aug 01, 2009 8:37 pm |
|
 |
Linux_User
I haven't seen my friends in so long
Joined: Tue May 05, 2009 3:29 pm Posts: 7173
|
Yep, it's definitely a scam, so I can only imagine that her account has been hacked. 
|
Sat Aug 01, 2009 8:44 pm |
|
 |
Nick
Spends far too much time on here
Joined: Thu Apr 23, 2009 11:36 pm Posts: 3527 Location: Portsmouth
|
Let's hope for her sake that she doesn't use the same username/password on other services, then. I know I do! 
_________________
|
Sat Aug 01, 2009 10:35 pm |
|
 |
jonbwfc
What's a life?
Joined: Thu Apr 23, 2009 7:26 pm Posts: 17040
|
Like err... here for example.
Man the barricades!
Jon
|
Sat Aug 01, 2009 11:11 pm |
|
 |
leeds_manc
I haven't seen my friends in so long
Joined: Thu Apr 23, 2009 8:19 pm Posts: 5071 Location: Manchester
|
That's a virus, not a hack.
|
Sat Aug 01, 2009 11:16 pm |
|
 |
Nick
Spends far too much time on here
Joined: Thu Apr 23, 2009 11:36 pm Posts: 3527 Location: Portsmouth
|
How do you know that? 
_________________
|
Sat Aug 01, 2009 11:18 pm |
|
 |
Linux_User
I haven't seen my friends in so long
Joined: Tue May 05, 2009 3:29 pm Posts: 7173
|
On a Mac? 
|
Sat Aug 01, 2009 11:24 pm |
|
 |
Nick
Spends far too much time on here
Joined: Thu Apr 23, 2009 11:36 pm Posts: 3527 Location: Portsmouth
|
She could have been using any machine though.
So either she was using a PC or she is the first victim of a virus infecting OS X in the wild.
_________________
|
Sat Aug 01, 2009 11:30 pm |
|
 |
jonbwfc
What's a life?
Joined: Thu Apr 23, 2009 7:26 pm Posts: 17040
|

He doesn't. The most likely thing - given Twitter user names are public - is a brute force attack against her account, rather than any sort of hack of a PC. They can brute force her (and probably a lot of other people's) twitter accounts from anywhere using a botnet, rather than having to go to the trouble of hacking a particular PC. Oddly, something similar happened to me recently. I have a hotmail account that I use very very rarely. It was hacked and a load of spam sent out to various accounts in my contact list. Most of them were defunct, and one of the others was me  . MS's official line is that I must have had my computer compromised and my password keylogged. This is odd considering 1) I hadn't used the account in quite some time, so they'd have had to grab my account and then sit on it for months, for no good reason at all. 2) I'm not entirely ignorant of computer security. The PC is use to log in to hotmail is behind a hardware firewall with virtually all ports routed to /dev/null. The PC itself also has a firewall with, again, a very limited number of ports open. 3) My hotmail address is essentially broadcast to the internet, because it's the account I have in anything I send to usenet. The chances of someone getting into my computer, keylogging it, grabbing the hotmail password, sitting on it for months without using any of the other pieces of info I type in, like the passwords to my online banking and credit card numbers and the like, seems to me to stretch things beyond the bounds of credulity. It seems to me that nabbing my email address off usenet then using a botnet to brute frce the password out of a publicly accessible system is much more straightforward. Occam's razor and all that. of course, MS/Google/Yahoo etc will never admit that people could have their accounts compromised this easily, because if they do people will abandon them en masse. Jon
|
Sun Aug 02, 2009 12:46 pm |
|
 |
leeds_manc
I haven't seen my friends in so long
Joined: Thu Apr 23, 2009 8:19 pm Posts: 5071 Location: Manchester
|
Because it's worded in exactly the same way as a virus I had for MSN, which my housemate downloaded. i don't see why you'd bother hacking someone's account just to propogate a message which is blatant spam, personal fraud yes, not junk mail.
|
Sun Aug 02, 2009 2:08 pm |
|
 |
ChurchCat
Doesn't have much of a life
Joined: Sat Apr 25, 2009 7:57 am Posts: 1652
|
If it was the first Mac virus I think we would have heard a bit more about it in the press.
_________________A Mac user 
|
Sun Aug 02, 2009 3:42 pm |
|
 |
Nick
Spends far too much time on here
Joined: Thu Apr 23, 2009 11:36 pm Posts: 3527 Location: Portsmouth
|
Oh god those things drive me mad. They make me laugh too though. At first you see just one person in your contact list with the message "DONT ACCEPT FILES ITS A VIRUS" and then there is a domino effect and before you know it, you are being bombarded by dozens of contacts trying to send you holidaypics.exe or something similar. 
_________________
|
Sun Aug 02, 2009 3:47 pm |
|
 |
jonbwfc
What's a life?
Joined: Thu Apr 23, 2009 7:26 pm Posts: 17040
|
You don't bother, it's all automated. Bunches of bots hammer away at a list of MS live/gmail/twitter accounts until they get in then read the contact list, dump the message out and send back the list of addresses in the contact list (which is actually the valuable bit, because they're much more likely to be valid email addresses than just randomly made up ones). Nobody has to actually do anything other than press 'go'. We're talking about thousands of PCs banging away at millions of accounts here. Vast economies of scale. It absolutely wouldn't be worth hacking someone's account to do this, so they're making the computers do what they're very good at - the same thing, over and over again, quickly. You pull a script down off the web, give it the text of a message to send and then upload it to a whole big bunch of computers. You don't even have to have a list of zombies, the script will even download that for you. I've seen these scripts, they're not even very complicated. Jon
|
Sun Aug 02, 2009 4:36 pm |
|
 |
big_D
What's a life?
Joined: Thu Apr 23, 2009 8:25 pm Posts: 10691 Location: Bramsche
|
And it is still spamming away.  Looks like Caz has taken the day off and is away from her machine(s).
_________________ "Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari
Executive Producer No Agenda Show 246
|
Sun Aug 02, 2009 4:50 pm |
|
 |
leeds_manc
I haven't seen my friends in so long
Joined: Thu Apr 23, 2009 8:19 pm Posts: 5071 Location: Manchester
|
I shall slightly re-word my earlier post: It sounds more like a virus than a hack to me. 
|
Sun Aug 02, 2009 5:09 pm |
|
|