Live data from Hacker News

Hackers take over prominent Twitter accounts in simultaneous attack

coindesk.com

891–900 of 1001 posts

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#891

Given how huge this hack is, and how little the BTC reward is going to be, I'm tempting to think this is either: - a test of a new hacking system - a demonstration to a big client - a first shot to threat some entity - a diversion while they get the real loot And that the BTC messages are just a way to justify it so it looks like a simple scam. Such a hack is worth way, WAY more than the few BTC it could bring.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

I remember last year around christmas/new year 2018/2019 a similar hack/leak/doxxing took place, targeting 994 (!!) mostly german politicians, celebrities and influencers. Massive amounts of private information (names, addresses, phone numbers, e-mails, DMs, contacts, online profiles, chat logs, private documents and even intimate details) where leaked. The data was published on a wide spread of public pastebins and etherpads. It took ages to take them down. The attacker had set up a labyrinth of links, files and passwords and even structured the data by topics and political parties.

Attack vector: Sim-Swapping. It was too easy. As soon as he got into one account, he got access to it's contacts and more phone numbers.

The attacker (0rbit) was a 20 year old student living at his parents home. He bragged about his hack to a online friend. This friend knew that 0rbit had been raided by the police years earlier. He betrayed him to the investigators and with the exact date of the raid the they were able looked up the old case and reveal his identity.

Previously on HN: https://news.ycombinator.com/item?id=18823286

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#892
post #887

Earlier quoted context omitted.

Very strange. Why exactly is it possible for any employee to tweet as any user? Unless the person who was targeted was the Database admin himself or something. Even then, how tech illiterate is this employee with such high permissions to fall for a social engineering attack? I would like to know what this employee's role was in the company. Also who did the social engineering?

Well, it's actually not that hard to fall for social engineering even if you're well educated about the topic. Have a listen to an interview Christopher Hadnagy gave on Darknet Diaries.

Here's the episode: https://darknetdiaries.com/episode/69/

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#893
post #383

Earlier quoted context omitted.

113k is a little reward?

This hack is (quite literally) worth billions of dollars. From market manipulation to geopolitical implications. So yes, 113k is peanuts.

Tweets are not nearly as important as you seem to think.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#894
post #883
post #767

Earlier quoted context omitted.

It looks like someone found a 0-day in the new API and wanted to use it before others did. Probably didn't help that the bug bounty for this would have been only 7k. How much does the Twitter employee who implemented this bug get paid? https://twitter.com/LiveOverflow/status/1283511782380908545

We now know it wasn't a 0 day. It was socially engineered access to internal tools. That's still a tricky one to lockdown.

More info on this https://techcrunch.com/2020/07/15/twitter-hacker-admin-scam/

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#895

I have a question to ask you all. If I wanted to study things to get to the point where internally/externally I could coordinate a hack of this magnitude, what things do I need to study? What are the technical things needed to pull something like this off? What are the social corporate things I needed to know to pull this off? I know that we don't have specifics, but I'm asking as a pure academic exercise how much I'…

Unfortunately majority of big breaches like this are a result of social hacking rather than some computer science magic. However to answer your question of how much you'd actually need to know? Decent networking and system understanding as well as how to apply this knowledge in reverse engineering. Finally you need loads of luck. Most of penetration testing is just throwing existing things at the system and generally…

Well that's what I'm asking about. What social hacking principles possibly were used here? What is the understanding that the attacker has about the people inside the company and how security is at companies like this to pull off a breach like this?

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#896
post #356

Twitter should suspend the entire platform until they can credibly fix this and prevent it in the future. An attacker could drop AMZN stock by 10% in minutes with just the wrong tweet from Bezos.

Even worse? How about POTUS declares war on China thru twitter? OMG, I just realized how dumb that would have been to say back in 2016. But these days?

As mentioned in a NYT article, Trump’s account is under “separate lock and key” which I think means it was not vulnerable to this threat. But yeah still super scary. Src: https://www.nytimes.com/2020/07/15/technology/twitter-hack-b...

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#897

Earlier quoted context omitted.

It could just be a relatively unsophisticated actor who stumbled upon a serious vulnerability and didn't know enough to market it to, eg, a state actor or whatever.

I remember last year around christmas/new year 2018/2019 a similar hack/leak/doxxing took place, targeting 994 (!!) mostly german politicians, celebrities and influencers. Massive amounts of private information (names, addresses, phone numbers, e-mails, DMs, contacts, online profiles, chat logs, private documents and even intimate details) where leaked. The data was published on a wide spread of public pastebins and…

It was not a hack. It was just a lot of doxxing. There was really nothing impressive about it.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#898
post #887

Earlier quoted context omitted.

Very strange. Why exactly is it possible for any employee to tweet as any user? Unless the person who was targeted was the Database admin himself or something. Even then, how tech illiterate is this employee with such high permissions to fall for a social engineering attack? I would like to know what this employee's role was in the company. Also who did the social engineering?

Well, it's actually not that hard to fall for social engineering even if you're well educated about the topic. Have a listen to an interview Christopher Hadnagy gave on Darknet Diaries.

Fair point. I still want to know how it happened and how the employee who's got to have very high level permissions managed to give access to the entire system including change user email and phone numbers.

Re: Hackers take over prominent Twitter accounts in simultaneous attack

#900
post #356

Earlier quoted context omitted.

Even worse? How about POTUS declares war on China thru twitter? OMG, I just realized how dumb that would have been to say back in 2016. But these days?

This hack could absolutely get people killed. There are several tweets I can think of from POTUS that would begin immediate military mobilization from an unfriendly country.

This is unlikely between nation states. The menagerie of diplomatic officers in every capital city prevents this from happening.

Well armed militia who don’t offer diplomatic representation — they are the ones to worry about.

Post reply on HN