Twitter Users Hit by Another Worm

Twitter Users Hit by Another Worm

Written By
Brian Prince
Brian Prince
Sep 27, 2010
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Twitter users were hit with yet another worm during the weekend.

This time, the tweets came bearing the message “WTF” with a link in tow. Clicking on the link automatically generated a post from the victim with a pornographic message.

“Clicking on the WTF link would take you to a webpage which contained some trivial code which used a CSRF (cross-site request forgery) technique to automatically post from the visitor’s Twitter account,” explained Graham Cluley, senior technology consultant at Sophos. “All the user sees if they visit the link is a blank page, but behind the scenes it has sent messages to Twitter to post from your account.”

Though Sophos did not know how many users were impacted, Sophos Senior Security Analyst Beth Jones said it was not “nearly as widespread” as last week’s onMouseOver worms, which affected hundreds of thousands of Twitter users. In that case, a cross-site scripting vulnerability was exploited by various people to send out multiple worms that among other things redirected users to porn sites.

As in that incident, the most recent attack snared some high-profile Twitter users, including blogger Robert Scoble.

“Chances are that the reason why this attack spread so speedily is that people were curious to find out what they would find at the end of a link only described as ‘WTF’,” Cluley blogged.

Twitter reported Sept. 26 that the malicious link is disabled and that the exploit has been fixed.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.