Earlier quoted context omitted.
I love this theory, but at the same time, I feel that it's unlikely. Without knowing how their back-end is put together, that'd be like... trying to smuggle in a robot into an office building to break into a safe that's inside without knowing the floor plan, what kind of knobs are on the doors, etc.
Could have paid/convinced/threatened an intern/employee to scope it out and then deployed the hack externally to bypass safety measures. Complicated but doable.
Hackers take over prominent Twitter accounts in simultaneous attack
651–660 of 1001 posts
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#652Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.
It can‘t really be the first three, because Twitter will fix this problem soon. So it would be wasting the exploit. It‘s either incompetence or your fourth option.
Why weren’t these tweets deleted immediately and a note pinned to every users feed?
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#653Is the attack now changing usernames to the BTC address or are these people just trolling? https://twitter.com/search?q=bc1qxy2kgdygjrsqtzq2n0yrf2493p8...
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#654Earlier quoted context omitted.
What was done was a guaranteed method of getting the method/exploit fixed in record time. If the perpetrator wanted to demonstrate, they would have targeted someone inconsequential that would not have put the problem on twitters radar. They blew their whole wad, likely on purpose, and there is nothing else planned.
Yeah, the idea that this is an initial step in something bigger doesn't make sense. If they wanted to exfiltrate data, they already did that previously. They very loudly burned their access, this seems a lot more like someone trying to monetize their access quickly before their access token expires - squeezing out the last few drops before they can no longer get into the system.
Someone (or someones) had to configure a message for each victim, they had to write the script to send all the tweets simultaneously, they probably had to test the script, they had to execute it. To me, that says they had enough time to think about what they were doing and weren't racing a very short expiration clock.
If I were at twitter I might try to investigate by looking for accounts that they might have used to test their script. If you could look for something like multiple accounts tweeting the same thing within 1 minute, in the past couple weeks, you could turn up some candidates for test accounts. You could further refine that by checking the messages sent, follower counts, etc. Maybe the hacker will leave behind clues on the script test account.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#655Earlier quoted context omitted.
Inkl bite: lets say I hack capable of doing this. How do I sell my hack?
Walk into the [country] embassy, probably (or twitter these days...)
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#656Elon Musk as well. Tweets still up, saying "Feeling greatful, doubling all payments sent to my BTC address! You send $1,000, I send back $2,000! Only doing this for the next 30 minutes." As of now, 121 people have sent cash totally more than 2.5BTC. Edit: Just seen @BillGates compromised as well, same bitcoin account. Edit 2: Elon's tweet seems to be getting removed, and then reposted again shortly after. About $40k…
My bet is that some Tweet posting API is missing a critical authentication check or the hackers found a way to bypass this check. I doubt someone could individually hack all these accounts.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#657Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#658Tweet from TwitterDev team yesterday: https://twitter.com/TwitterDev/status/1283068902331817990 > 2 days to go… #TwitterAPI https://twitter.com/TwitterDev/status/1283433096780677122 > Thank you to all of you who have engaged with us and shared your feedback. Your input has been vital, and we’re committed to continuing these conversations with you. There’s so much more we’re doing to build a better #TwitterAPI… and Ea…
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#659Earlier quoted context omitted.
a temp fix is to modify the backend to prevent anyone from pasting a bitcoin address or any long string of numbers and letters that may resemble such an address
Cryptocurrency scams have been going on for years despite the fix being an easy "if reply to a high-profile account and contains the words "bitcoin" or "giveaway" then ban". If they couldn't (or didn't want to) do it then I very much doubt they can do it now.
Re: Hackers take over prominent Twitter accounts in simultaneous attack
#660Tweet from TwitterDev team yesterday: https://twitter.com/TwitterDev/status/1283068902331817990 > 2 days to go… #TwitterAPI https://twitter.com/TwitterDev/status/1283433096780677122 > Thank you to all of you who have engaged with us and shared your feedback. Your input has been vital, and we’re committed to continuing these conversations with you. There’s so much more we’re doing to build a better #TwitterAPI… and Ea…
Nice catch, this may be what it was. Edit: looks like an admin panel was the culprit https://news.ycombinator.com/item?id=23853786