On mySimon: Kidkraft Savannah Dollhouse
BNET Business Network:
BNET
TechRepublic
ZDNet

February 4th, 2009

Commercial Twitter spamming tool hits the market

Posted by Dancho Danchev @ 9:02 am

Categories: Malware, Phishing, Social Networking Applications, Spam and Phishing, Web 2.0

Tags: Security, Spam Tool, TweetTornado, Twitter, Micro-blogging, Social Networks, Dancho Danchev

Last week, a commercial Twitter spamming tool (tweettornado.com) pitching itself as a “fully automated advertising software for Twitter” hit the market,  potentially empowering phishers, spammers, malware authors and everyone in between with the ability to generate bogus Twitter accounts and spread their campaigns across the micro-blogging service.

TweetTornado allows users to create unlimited Twitter accounts, add unlimited number of followers, which combined with its ability to automatically update all of bogus accounts through proxy servers with an identical message make it the perfect Twitter spam tool.

TweetTornado’s core functionality relies on a simple flaw in Twitter’s new user registration process. Tackling it will not render the tool’s functionality useless, but will at least ruin the efficiency model. Sadly, Twitter doesn’t require you to have a valid email address when registering a new account, so even though a nonexistent@email.com is used, the user is still registered and is allowed to use Twitter.

So starting from the basics of requiring a validation by clicking on a link which will only be possible if a valid email is provided could really make an impact in this case, since it its current form the Twitter registration process can be so massively abused that I’m surprised it hasn’t happened yet. Once a Twitter spammer has been detected, the associated, and now legitimate email could be banned from further registrations, potentially emptying the inventory of bogus emails, and most importantly making it more time consuming for spammers to abuse Twitter in general.

If TweetTornado is indeed the advertising tool of choice for Twitter marketers, I “wonder” why is the originally blurred by the author Twitter account used in the proof (twitter.com/AarensAbritta) currently suspended, the way the rest of the automatically registered ones are? Pretty evident TOS violation, since two updates and 427 followers in two hours clearly indicate that a spammer’s tweeting.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 18 Talkback(s)
RE: there are already similar tools out there
Mr. Tweet, http://mrtweet.net/ appears to work in a somewhat similar way, it "suggests" people to you but is not as automatic. But essentially it is still a "marketing" tool, just angled to look more friendly.... (Read the rest)
Posted by: absent Posted on: 02/08/09 You are currently: a Guest | | Terms of Use
Is this English?  wgg | 02/04/09
English  marta@... | 02/04/09
RE: Commercial Twitter spamming tool hits the market  jhimes | 02/04/09
RE: Commercial Twitter spamming tool hits the market  marta@... | 02/04/09
I'll second that.  harry.n | 02/04/09
Great...  bishofthedump | 02/04/09
RE: Commercial Twitter spamming tool hits the market  gabrielbear@... | 02/04/09
RE: Commercial Twitter spamming tool hits the market  maremel | 02/04/09
Simple Solution - Read before you Follow  webservant2003@... | 02/04/09
RE: Commercial Twitter spamming tool hits the market  vilppuu@... | 02/04/09
RE: Commercial Twitter spamming tool hits the market  vangie2280 | 02/04/09
RE: Commercial Twitter spamming tool hits the market  nikkipilkington | 02/05/09
How to twitter market without spamming  trustseo.com | 02/05/09
RE: Commercial Twitter spamming tool hits the market  Patrick Neylan | 02/05/09
Tweet Tornado Replies To This Blog.  tweettornado | 02/05/09
Die you scum sucking roach of humanity  Kaiwai | 02/06/09
Twitter Spam Yuck  Andrew Merrick | 02/05/09
RE: there are already similar tools out there  absent | 02/08/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here