FourSquare & Hacked Twitter Accounts (Google Wizard?)
My twitter account was hacked, one spam message posted, and my account subsequently suspended. The spam was the Google Wizard message in the following format:
"Up to $240.30 so far today!!! i'll tweet another update later!! check out http:/ /G O 0GLE-WIZARD D.com"
"I've been doing this for 8 days so far, up to $142.90 so far - http:/ /G O 0GLE-WIZARD.com"
"Today was so exciting! Made $124 in 20 minutes! if ur interested, go read: http:/ /G O 0GLE-WIZARD.com"
My twitter usename is(was !?) "aliencam"
this happened to hundreds of users, and at least one other (@tomloverro via http://community.norton.com/t5/Ask-Ma... ) was using foursquare
read about this hack in these places:
http://community.norton.com/t5/Ask-Ma...
http://getsatisfaction.com/twitter/to...
http://blog.aliencam.net/2009/07/goog...
So did a problem with foursquare compromise our twitter accounts? Were any other foursquare/twitter users "hacked" ??? I don't want to blame foursquare yet, but if lots of it's users were the ones with problems on twitter...
"Up to $240.30 so far today!!! i'll tweet another update later!! check out http:/ /G O 0GLE-WIZARD D.com"
"I've been doing this for 8 days so far, up to $142.90 so far - http:/ /G O 0GLE-WIZARD.com"
"Today was so exciting! Made $124 in 20 minutes! if ur interested, go read: http:/ /G O 0GLE-WIZARD.com"
My twitter usename is(was !?) "aliencam"
this happened to hundreds of users, and at least one other (@tomloverro via http://community.norton.com/t5/Ask-Ma... ) was using foursquare
read about this hack in these places:
http://community.norton.com/t5/Ask-Ma...
http://getsatisfaction.com/twitter/to...
http://blog.aliencam.net/2009/07/goog...
So did a problem with foursquare compromise our twitter accounts? Were any other foursquare/twitter users "hacked" ??? I don't want to blame foursquare yet, but if lots of it's users were the ones with problems on twitter...
1
person has this problem
I have this problem, too!
Tell me when someone solves it.
The more people who report this problem, the more it gets noticed.
The more people who report this problem, the more it gets noticed.
The company has acknowledged this problem.
Create a customer community for your own organization
Plans starting at $19/month
-
Inappropriate?I'm on it.
Just FYI: Did a little investigation and I'm seeing that a lot of Twitter users that are not on foursquare have reported this too.
I’m anxious
1 person says
this solves the problem
-
Inappropriate?As a start, I looked at recent Twitter searches for this -- a whole slew of people (not related to foursquare) are having these issues: http://search.twitter.com/search?q=go...
I’m anxious
-
Inappropriate?Okay good, glad to hear non-fourswuareers are affected so its probably not your fault :P
thanks for the really quick response!
I’m still suspended from twitter.
-
Inappropriate?So if it's not Foursquare - where is Go0gle-wizards getting the Twitter IDs and passwords?
-
No clue... My password was very secure, FourSquare and TwitterBar were the only two apps I have allowed... -
Inappropriate?It's great to know that it wasn't just FourSquare users who got hacked. I wonder if there is a problem with the Twitter API or Twitter servers themselves (clearly they've had security issues...per TechCrunch)?
BTW, I was NOT blaming FourSquare or Sawhorse media in my post on the Norton Community forums. I was trying to provide all relevant info possible and I hope Dennis and Naveen realize that :-)
I love FourSquare!
-@tomloverro -
Inappropriate?btw:
1. we're using oauth for twitter. your twitter password is never stored or revealed to anyone.
2. if any of your twitter clients were at fault, i'm sure twitter would have found them and locked their access. (incidentally, i noticed that all the spammy tweets were actually sent as 'web' instead of 'from an application'.)
3. the tweets about the spam (and the spam itself) seems to have died down. i'm guessing twitter's found the culprit and has locked it down
I’m anxious
-
Inappropriate?Regarding (2) tweets posted via the API from "anonymous" sources (i.e. unregistered Apps) appear as "web" - sort of a bug in Twitter
So now if we know it wasn't FourSquare, it better not be swept under the rug as to where the breach came from, assuming Twitter knows. So what gives, Twitter? How did "Google Wizard" get the credentials?
-
Inappropriate?Actually it looks like I have to correct myself. Up until very recently, tweets posted via the API showed as "from web" but they now appear to show as "from API" for unregistered sources. Perhaps this is actually something they changed as a result of the "Google Wizard" spam because I'm pretty sure when that spam was flowing out, Twitter had not made this change.
Loading Profile...



EMPLOYEE

