On MovieTome: Lord of the Rings' lawsuit settled!
BNET Business Network:
BNET
TechRepublic
ZDNet

April 17th, 2009

Twitter worm author gets a job at exqSoft Solutions

Posted by Dancho Danchev @ 11:11 am

Categories: Browsers, Exploit code, Hackers, Malware, Passwords, Pen testing, Social Networking Applications

Tags: Job, XSS, Web Application, Worm, Twitter, Mikey Mooney, Cyberthreats, Dancho Danchev, Security, Viruses And Worms

UPDATE: Mikeyy Mooney of Stalk Daily gets Hacked. Here’s more info.

Now that was so fast that even Owen Thor Walker (AKILL) and Michael Calce (Mafiaboy) should envy the short cybercrime-to-job offer cycle here. 17 years old Mikeyy Mooney, the author/spreader of StalkDaily/Mickeyy XSS worm that exploited Twitter through trivial web application vulnerabilities during the weekend, has landed a job as a web applications developer at exqSoft Solutions.

Do you fancy him? I don’t, and so do others. Here’s why you shouldn’t, as well as the implications of what is slowly becoming a dangerous trend.

Image the villains vs cybercrime task force, an internationally recognized team including Romanian phishers, ex-carding kings now politicians, initiators of the first major DDoS attack that hit the most popular web sites in 2000 (including ZDNet) and who else are we missing? Oh yeah, the Pinch malware authors, but “sadly” they’re in jail.

Cutting the sarcasm, this most recent hire indicates an emerging trend and sends a wrong signal. Namely, that conducting unethical pen-testing against a top web property’s web applications in order to put the proof of concept code into action by launching a worm in order to prove the obvious, can indeed land you a job offer. A similar case happened in July, 2008, when a XSS worm at Justin.tv infected 2,525 profiles in order to prove the obvious - the site’s “wormability”. Back then I pointed out the same concern :

Now, proof of concept of what exactly remains questionable, since if the research community was to exploit every site vulnerable to SQL injections or high profile sites vulnerable to critical XSS flaws, in order to embedd a counter within and then come up with fancy graphs saying this is the number of people that could have been affected by this flaw, we would be dealing with more PoCs next to the real security incidents executed by malicious parties.

It’s important to point out that exqSoft Solutions appears to be fully aware of the basics of guerrilla PR campaigns. The company established in 2000 is nowhere to be found in the public space, that’s of course until it hires Mikeyy Mooney to make a mainstream media appearance for the very first time.

Who’s next on the hiring spree? From a web application security perspective, that could easily be the Asprox botnet authors, having SQL injected over 1.5 million pages (500, 000 sites), making Mikeyy’s XSS worm look like a bit of a shy one.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 14 Talkback(s)
RE: Twitter worm author gets a job at exqSoft Solutions
In the immortal words of Run D.M.C.
"It's like that, that's the way is, HUH!"

Right wrong or retarded, the best way to get yourself a job and sidestep the whole college thing, is to exploit ... (Read the rest)
Posted by: pwn0tr0n Posted on: 04/23/09 You are currently: a Guest | | Terms of Use
Make sandboxes availible  dszimmer | 04/17/09
That's a good idea, but...  Tony Agudo | 04/19/09
Apparently, crime does pay  ThePrairiePrankster | 04/17/09
RE: Twitter worm author gets a job at exqSoft Solutions  ceo@... | 04/17/09
He SHOULD have a job, busting rocks in prison!  No_Ax_to_Grind | 04/18/09
clearly your middlename is Palmer  abdulbijur | 04/19/09
RE: Twitter worm author gets a job at exqSoft Solutions  jks22835 | 04/18/09
RE: Twitter worm author gets a job at exqSoft Solutions  Steve KTG | 04/19/09
RE: Twitter worm author gets a job at exqSoft Solutions  gabrielbear@... | 04/20/09
at least we now know  walkerjian@... | 04/20/09
Definately the wrong decision  10W1V1 | 04/21/09
RE: Twitter worm author gets a job at exqSoft Solutions  phatkat | 04/21/09
RE: Twitter worm author gets a job at exqSoft Solutions  stanad@... | 04/21/09
RE: Twitter worm author gets a job at exqSoft Solutions  pwn0tr0n | 04/23/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here