Off The Rails: Twitter, Passwords And Twittertrain

June 9, 2009 by admin  
Filed under Security News


5 views   Leave a Comment

If someone promised they could get you hundreds of new followers on Twitter every day would you believe them?

Would you be prepared to hand over your Twitter username and password to them?

Well, a website called Twittertrain is promising to do just that – inviting fans of the micro-blogging website to enter their credentials.

However, what’s worst of all is that hundreds and hundreds of Twitter users are currently advertising the site, all with the same message:

OMG WOW Im getting 100s of followers a day. Check out this site http://twittertrain.net

I don’t think I’m stretching my neck out too far if I make the prediction that I doubt these users are choosing to advertise the Twittertrain site. My guess is that someone else is posting the messages promoting the Twittertrain site. Now, who on earth would be motivated to do that I wonder?

And what are they planning to do with all these usernames and passwords?

Twitter user advertising the Twittertrain website

Here’s a short video I’ve made demonstrating the scale of the problem:

Off the rails: Twitter, passwords and Twittertrain from SophosLabs on Vimeo. (The video is also available on YouTube).

Of course, you’re playing a very dangerous game if you hand over your username and passwords to a website like this. There’s no promise that you will get the hundreds of new followers that you are dreaming of, and furthermore hackers might break into your account to send spam, spread malware or launch further phishing attacks.

Certainly the number of Twitter users promoting Twittertrain today suggests that something very fishy is going on.

If you did make the mistake of giving Twittertrain your username and password, change your passwords immediately

by Graham Cluley, Sophos


Related posts:

  1. ‘More followers’ spam hits Twitter accounts
  2. Video of Twitter phishing: The BZPharma ‘LOL this is funny’ attack (Video)
  3. All Twitter Users Have 0 followers and 0 following !
  4. Splunk warns that it exposed users’ passwords
  5. Latest Britney Spears Twitter Hack Highlights TwitPic Weakness (Britney Spears isn’t dead)

Speak Your Mind

Tell us what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!