<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; twitter</title>
	<atom:link href="http://praetorianprefect.com/archives/tag/twitter/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Thu, 19 Jan 2012 03:59:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>An Insult to Romanians Published on the Twitter Account of the French Foreign Ministry</title>
		<link>http://praetorianprefect.com/archives/2010/09/an-insult-to-romanians-published-on-the-twitter-account-of-the-french-foreign-ministry/</link>
		<comments>http://praetorianprefect.com/archives/2010/09/an-insult-to-romanians-published-on-the-twitter-account-of-the-french-foreign-ministry/#comments</comments>
		<pubDate>Fri, 17 Sep 2010 17:00:39 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=4927</guid>
		<description><![CDATA[The Twitter account of the French Foreign Ministry was compromised, and an anti-Romanian message posted, in the midst of the deportation of some 100 Roma from the country.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/09/an-insult-to-romanians-published-on-the-twitter-account-of-the-french-foreign-ministry/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Persistent XSS on Twitter.com</title>
		<link>http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/</link>
		<comments>http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 08:32:11 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[post-wide]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=4423</guid>
		<description><![CDATA[Twitter user 0wn3d_5ys has demonstrated a persistent cross site scripting (XSS) vulnerability he found on  June 21st using his own Twitter account (visit at your own risk) that appears to be due to a lack of input validation of the application name field when accepting new requests for Twitter applications.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>Going After BP</title>
		<link>http://praetorianprefect.com/archives/2010/06/going-after-bp/</link>
		<comments>http://praetorianprefect.com/archives/2010/06/going-after-bp/#comments</comments>
		<pubDate>Wed, 09 Jun 2010 20:43:09 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Web Site Defacement]]></category>
		<category><![CDATA[brute forcing]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[remote file inclusion]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=4050</guid>
		<description><![CDATA[BP continues to be the subject of criticism following the Deepwater Horizon oil spill, and the hacking community appears to be taking exception to some of BP's recent public relations activities in the online arena.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/06/going-after-bp/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>We shall strike if the leader orders: Twitter Struck by Iranian Cyber Army</title>
		<link>http://praetorianprefect.com/archives/2009/12/we-shall-strike-if-the-leader-orders-twitter-struck-by-iranian-cyber-army/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/we-shall-strike-if-the-leader-orders-twitter-struck-by-iranian-cyber-army/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 16:32:07 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Web Site Defacement]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2500</guid>
		<description><![CDATA[At some time around 10pm on Thursday, users going to Twitter.com were served the page below with a banner reading "This site has been hacked by the Iranian Cyber Army". Also, mowjcamp.org, a site for supporters of Mir-Hossein Mousavi Khameneh a candidate who ran against Mahmoud Ahmadinejad in the 2009 Iranian presidential election, has been serving a similar defacement since at least December 16th and continues to do so. The motive appears to be activism in support of Iran's current Islamic regime. The attack vector was a bad actor using an id and password assigned to Twitter to log in to the <a href="https://dyn.com/user">administrative portal</a> of managed DNS service provider <a href="http://dyn.com/">Dyn</a>.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/we-shall-strike-if-the-leader-orders-twitter-struck-by-iranian-cyber-army/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>“Hi. This you?? LOL” Twitter Attack Snares Kevin Mitnick</title>
		<link>http://praetorianprefect.com/archives/2009/11/%e2%80%9chi-this-you-lol%e2%80%9d-twitter-attack-snares-kevin-mitnick/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/%e2%80%9chi-this-you-lol%e2%80%9d-twitter-attack-snares-kevin-mitnick/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 16:16:33 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[mitnick]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1811</guid>
		<description><![CDATA[Historically the “Is this you?” style Twitter attack seems to be seeded by either an original break in to the victim’s Twitter account, or that user having provided his or her credentials to a phishing style web site made to look like Twitter as the attack propagates through the popular micro-blogging service. This time around however, the <a href="http://www.twitter.com/KevinMitnick">account</a> of security consultant and former cracker Kevin Mitnick was caught up in this generic, untargeted Twitter “worm”.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/%e2%80%9chi-this-you-lol%e2%80%9d-twitter-attack-snares-kevin-mitnick/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Not the Haus of Gaga too</title>
		<link>http://praetorianprefect.com/archives/2009/11/not-the-haus-of-gaga-too/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/not-the-haus-of-gaga-too/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 08:20:58 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[brute forcing]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1723</guid>
		<description><![CDATA[Around 9pm EST on Monday the Twitter account of pop singer Lady Gaga, <a href="http://www.twitter.com/ladygaga">@ladygaga</a> was cracked in to and a series of messages added to her tweet stream. This is the second high profile Twitter account to be cracked in the last few days, on Friday the account of pop singer Britney Spears, @BritneySpears, started professing sympathy for the devil. The Lady Gaga one is interesting though, because like an homage to old school cracks of the past, the attackers appear to have left their name. Further these are two high profile accounts broken into after Twitter has implemented at least three major changes to their web site's authentication process.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/not-the-haus-of-gaga-too/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Sir, the floor wishes to hear no more about your colon.</title>
		<link>http://praetorianprefect.com/archives/2009/10/sir-the-floor-wishes-to-hear-no-more-about-your-colon/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/sir-the-floor-wishes-to-hear-no-more-about-your-colon/#comments</comments>
		<pubDate>Fri, 30 Oct 2009 23:22:16 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[twishing]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1340</guid>
		<description><![CDATA[The <a href="http://praetorianprefect.com/archives/2009/10/a-twitter-worms-brilliant-variation/">Twitter worm/twishing attack of the other day</a> has caught some interesting casualties in its net, most notably <a href="http://www.marcorubio.com/">Marco Rubio</a> a former Speaker of the Florida House of Representatives and a viable candidate for one of Florida's Senate seats in 2010 and <a href="http://www.zachwamp.com/">Zach Wamp</a>, a candidate for Governor of Tennessee and a 14 year U.S. congressional representative.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/sir-the-floor-wishes-to-hear-no-more-about-your-colon/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A twitter &#8220;worm&#8217;s&#8221; brilliant variation</title>
		<link>http://praetorianprefect.com/archives/2009/10/a-twitter-worms-brilliant-variation/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/a-twitter-worms-brilliant-variation/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 21:55:03 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[money mule]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1285</guid>
		<description><![CDATA[A new twitter worm is being reported making the rounds this morning, which is actually an expertly crafted variant of the worm we reported <a href="http://praetorianprefect.com/archives/2009/09/rofl-this-you-on-here-the-latest-twitter-worm/">back on September 24th</a>. The variant has changed the direct message from "ROFL, this you on here?" to "hi. this you on here?". The bad actor in China has also used a new URL, but with the same Twitter login landing page identifiable by its stray HTML brace ">" following the line under 'Sign in to Twitter'. This important difference in wording should allow for a spate of new captured twitter credentials.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/a-twitter-worms-brilliant-variation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Breaking Twitter (authentication)</title>
		<link>http://praetorianprefect.com/archives/2009/09/breaking-twitter-authentication/</link>
		<comments>http://praetorianprefect.com/archives/2009/09/breaking-twitter-authentication/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 17:26:54 +0000</pubDate>
		<dc:creator>Jeremy Rossi</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[tweethon]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=530</guid>
		<description><![CDATA[But wait you say, are you trying to tell us that brute force password attacks will move to the API when I just read on the Twitter API wiki that the API severely limits the rate of calls you are allowed to make to it (200/hour/IP for authenticated requests without whitelisting)?  That should be a mitigating control.  Should be, but isn't, because it is not enforced on all of the API calls.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/09/breaking-twitter-authentication/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ROFL this you on here? The latest Twitter Worm</title>
		<link>http://praetorianprefect.com/archives/2009/09/rofl-this-you-on-here-the-latest-twitter-worm/</link>
		<comments>http://praetorianprefect.com/archives/2009/09/rofl-this-you-on-here-the-latest-twitter-worm/#comments</comments>
		<pubDate>Thu, 24 Sep 2009 08:25:29 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[captcha]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[money mule]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=484</guid>
		<description><![CDATA[At 2pm on Wednesday 9/24, wide scale reports started showing up on Twitter that a new Twitter worm sends you a direct message with the content “rofl this you on here? http://videos.twitter.secure-logins01.com”.  The link opens a Twitter style log in page (albeit Twitter’s previous version of this page, they have a new one) which, except for being an old version and a stray angle bracket is convincing.  Upon logging in the user’s credentials are stolen, and presumably direct messages are sent to each follower that user has.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/09/rofl-this-you-on-here-the-latest-twitter-worm/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Snort is Tweeting</title>
		<link>http://praetorianprefect.com/archives/2009/04/snort-is-tweeting/</link>
		<comments>http://praetorianprefect.com/archives/2009/04/snort-is-tweeting/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 04:12:27 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=74</guid>
		<description><![CDATA[Network engineer Leon Ward of SourceFire has taken the unusual step of publishing his intrusion detection system (IDS) alerts over Twitter, the popular microblogging platform.  If you are so inclined, you can monitor his IDS along with your own, by following <a href="https://twitter.com/SnortIDS">@SnortIDS</a> on <a href="http://www.twitter.com">Twitter</a>.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/04/snort-is-tweeting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

