« Todays Top Tags, Bookmarks and News Review of Apple Boot Camp 1.2 Beta »
First Twitter Vulnerability
For all you people who are just crazy about Twitter, a vulnerability has been posted that will allow you to post to someone else’s twitter account. Since twitter uses caller id to authenticate users, it is very easy to post to someone else’s account since it is so easy to spoof the caller id number. Fakemytext.com is just one example of a site that will help you do just that.
Got friends on Twitter? Know their phone number? That?s all you need to take over their account and start posting messages in their name.
A similar exploit affects Jott, another service revolving around phone-based updates.
The vulnerability stems from the fact that both services use caller ID to authenticate users, but unfortunately caller ID is notoriously easy to spoof. In fact there?s a website designed to do just that ? fakemytext.com
By spoofing your caller ID, an attacker could post Twitter messages in your name.
Nitesh Dhanjani over at O?Reilly details the hacks and claims to have successfully exploited the vulnerabilities on both services. Source: Twitter Vulnerability: Spoof Caller ID To Take Over Any Account
The vulnerability was first detailed on the Oreilly.net website:
- I registered at fakemytext.com, a SMS spoofing service.
- Since the fakemytext.com service is based in the UK, I went through the Twitter FAQ and noted their UK based SMS number: +44-7781-488126.
- I sent the following SMS via fakemytext.com to +44-7781-488126 with the ?From? number set to my phone number: ?Testing via http://www.fakemytext.com/ . This better not work!?
- I checked my Twitter page, and sure enough, it was updated with the above SMS message. This means that anyone who knows a Twitter user?s cell phone number can update that persons Twitter page.
Source: Twitter and Jott Vulnerable to SMS and Caller ID Spoofing
Jott, a service that allows people to update people on important events is also vulnerable, as well as any other sites that use some form of authentication using caller id. The writers suggest a pin number to keep people from being able to exploit this.
I have created a Twitter page for security notifications and updates here, security.
Added: Just finished reading the comments on the Oreilly site, an engineer from Twitter chimes in and he’s not too happy about the disclosure.
I don’t think we were given nearly enough time to respond before this article was published, but that’s my personal opinion and not the opinion of Obvious.
It doesn’t take a genius to see that if every SMS-based application out there is vulnerable to spoofing, it’s probably a protocol-level flaw.
That said, doing the research involved to make a security recommendation to the mobile carriers would have taken real effort on the part of the author. Why bother when cheap hacks like this are easy and fun?
So, the Twitter engineer thinks the author should’ve tried to change how caller id works instead of posting the disclosure and letting everyone know it is possible. I think he’s been up to late working on a solution to something they should have tested to start with, was no one thinking about security when this was setup? The author in reply said,
SMS was never designed to be used for authentication, just as the From: address in a email was never designed to be something to authenticate against.
And he is correct. As far as I know, caller id was just to let people know who called or are calling, kind of like looking through the peephole when someone knocks at your door, it wasn’t designed to give people access to something. That’s like someone knocking on your door, seeing the peephole and walking on in because they must know who you are. Grow up and take some responsibility for your applications.
Popular Tags
-
.net Framework
180solutions
AACS
access your computer
Access Your PC from Anywhere
Adware
Aero
Alex Eckelberry
Alienware
alienware computer deals
alienware coupons
AMD
antivirus
Antivirus XP 2008
AOL
Apple
Apple TV
Astronomy
Back to School
Backup
BackupHDDVD
Bill Gates
Blizzard
Blogging
Blu-ray
boot up
Botnets
Broadband
Browsers
Buy.com Computer Deals
CallManager
CES
Cisco
Cisco Call Manager
command line
computer bargains
computer coupons
computer deal
Computer Deals
Computer Forensics
Control Panel
Copy DVDs
Core 2 Duo
Dell
dell.com
Dell Computer Deals
Dell Computers
Dell Coupons
dell laptop deals
Dell XPS
Detailed Bookmarks
Digg
Domains
DoS
DoubleClick
Drivers
DRM
DVD
eBay
Education
Email
Engadget
Excel
FAT
File Recovery
Firefox
Gadgets
gaming computers
gaming laptops
Gaming News
Gateway
Gears of War
Gears of War Glitches
Gears of War Tips
Gears of War Videos
GeoRSS
Gizmodo
Gmail
Google
Google Checkout
Google Desktop
Google Docs
Google Earth
Google earth layers
Google Earth Videos
Google Maps
Google Pack
gotomypc.com
GPS
Halo 2
Halo 3
hard disk
Hardware
HD DVD
HDTV
hdtv-deals
How To
HP
HP Computer Deals
hp computers
HP Coupons
Hybrid Hard Drives
IBM
IBM AS/400 and iSeries
IE7
IE8
Instant Messaging
Intel
Internet Explorer
iPhone
iPod
iTunes
J&R Computer Deals
Joost
Julie Amero
KML
Lenovo
Lenovo Computer Deals
Linux
Live
Longhorn Server
Mac OS X
Malicious Websites
Malware
messenger
Microsoft
Microsoft News
Microsoft Office
Microsoft Security Bulletin
Microsoft Surface
MP3 player
MPAA
MSN Messenger
MySpace
MySQL
Networking
NTFS
Office 2007
Office Genuine Advantage
Office News
Office XP
OGA
online shopping
Opera
Overstock Computer Deals
Overstock Coupons
Panda
PatchGuard
pc access
pc remote access
phishing
Photoshop
Picasa
Picasa Web Albums
Piracy
PlaysForSure
PlayStation 3
porn
Privacy
Protect Children Online
PS3
RAM
RC1
Readyboost
reboots
registry
remote access
remote access software
Remote Assistance
remote connection
remote control computer
remote control pc
remote desktop
remote desktop administration
Remote Desktop Connection
Reviews
RIAA
Sandisk
Screensaver
Screen Savers
screensavers
Second Life
Security
service pack
Service Packs
Services
Shutdown Problems
Sidebar Gadgets
Silverlight
SiteAdvisor
Skins
Skype
Smartphones
Social Engineering
Social Networks
Software
Sony
Sony Computer Deals
Sony Coupons
SP1
SP2
Spam
spyware
Spyware Info
Startup Problems
Steve Jobs
Symantec
Tablet PC
Techmeme
Tech News
Televisions
Themes
This Site
thumb drive
TigerDirect
Tigerdirect.com
Tigerdirect Computer Deals
Tips
Toshiba
Toshiba Computer Deals
Toshiba Coupons
toshiba laptop reviews
Toshiba Satellite
Twitter
Ubuntu
UI
upgrade
USB
Verizon
Video Conferencing
Video Games
Video iPod
Videos
Virtualization
Virtual Machines
Virus Info
Vista Gadget
VML
vml-exploit
VoIP
vulnerability
Walmart Computer Deals
Wayne Porter
WGA
White Papers
Wi-Fi
WiFi
Wii
Windows
Windows 7
Windows 7 Videos
Windows 2000
Windows 2003
Windows Defender
Windows Explorer
Windows Genuine Advantage
Windows Home Server
Windows Live
Windows Live Drive
Windows Live Messenger
Windows Longhorn Server
Windows Media Player
Windows Messenger
Windows Mobile
Windows Readyboost
Windows Readydrive
Windows Server
Windows Server 2008
Windows Update
Windows Vista
Windows Vista Sidebar
Windows Vista Themes
Windows Vista Videos
Windows XP
Windows XP Themes
Windows XP Tips
Windows XP Tweaks
WinFX
Wireless
Wireless networking
WMF
Word
World of Warcraft
world of warcraft mods
WOW
WOW mods
www.gotomypc.com
X-Cleaner
Xbox
Xbox 360
Xbox Live
Xbox Live Marketplace
XPS
Yahoo!
YouTube
Zango
Zune
Zune Marketplace
Zune Phone
Zune Tips
No Comments »
No comments yet.
RSS feed for comments on this post.
| TrackBack URI