<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Social Threat &#124; Who said social meant secure? &#187; Twitter</title>
	<atom:link href="http://socialthreat.com/tag/twitter/feed/" rel="self" type="application/rss+xml" />
	<link>http://socialthreat.com</link>
	<description>Who said social meant secure?</description>
	<lastBuildDate>Sat, 18 Jun 2011 03:07:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Twitter goes after phishing and malware</title>
		<link>http://socialthreat.com/2010/03/15/twitter-goes-after-phishing-and-malware/</link>
		<comments>http://socialthreat.com/2010/03/15/twitter-goes-after-phishing-and-malware/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 12:00:09 +0000</pubDate>
		<dc:creator>Scott Vowels</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://socialthreat.com/?p=307</guid>
		<description><![CDATA[
			
				
			
		
Last week Twitter announced that they had installed a service that will inspect some of the URLs that are submitted through its systems.  The issue they&#8217;re trying to solve is primarily in shortened URLs which hide the destination address.  It&#8217;s been used by bad guys to hide malicious destinations.  Dave mentioned this technique a couple 


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F15%2Ftwitter-goes-after-phishing-and-malware%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F15%2Ftwitter-goes-after-phishing-and-malware%2F&amp;style=normal&amp;service=bit.ly&amp;hashtags=malware,Phishing,Twitter" height="61" width="50" /><br />
			</a>
		</div>
<p>Last week Twitter announced that they had installed a service that will inspect some of the URLs that are submitted through its systems.  The issue they&#8217;re trying to solve is primarily in shortened URLs which hide the destination address.  It&#8217;s been used by bad guys to hide malicious destinations.  <a href="http://socialthreat.com/2010/02/22/a-new-phishing-scam-on-twitter/">Dave mentioned</a> this technique a couple weeks ago and gave some great tips on how to avoid the being a victim.  Maybe the Twitter security crew was listening?</p>
<p>In the <a href="http://blog.twitter.com/2010/03/trust-and-safety.html">announcement</a>, Twitter mentions that they&#8217;ll focus on direct messages and email notifications about direct messages.  I applaud the effort and hope it&#8217;s effective.  I wanted to point this out and give Twitter props for working on the problem.  We&#8217;ll have to see how effective it is but it&#8217;s great to see an attempt toward progress.</p>
<p>Hopefully we&#8217;ll see more news like this from other social media providers.</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://socialthreat.com/2010/03/15/twitter-goes-after-phishing-and-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hundreds of Twitter accounts sending out spam</title>
		<link>http://socialthreat.com/2010/03/08/hundreds-of-twitter-accounts-sending-out-spam/</link>
		<comments>http://socialthreat.com/2010/03/08/hundreds-of-twitter-accounts-sending-out-spam/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 14:15:55 +0000</pubDate>
		<dc:creator>Davezilla</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[API]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://socialthreat.com/?p=273</guid>
		<description><![CDATA[
			
				
			
		
Looks as though a third party app was hit for a phishing scam that has allowed the perps to appear to take over hundreds of Twitter accounts. According to Mashable, since all of the spammed tweets mention coming from the API, the accounts themselves are probably still OK. It&#8217;s the app they&#8217;ve allowed access to 


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F08%2Fhundreds-of-twitter-accounts-sending-out-spam%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F08%2Fhundreds-of-twitter-accounts-sending-out-spam%2F&amp;style=normal&amp;service=bit.ly&amp;hashtags=API,Phishing,Twitter" height="61" width="50" /><br />
			</a>
		</div>
<p>Looks as though a third party app was hit for a phishing scam that has allowed the perps to appear to take over hundreds of Twitter accounts. <a href="http://mashable.com/2010/03/06/twitter-accounts-hacked/">According to Mashable</a>, since all of the spammed tweets mention coming from the API, the accounts themselves are probably still OK. It&#8217;s the app they&#8217;ve allowed access to that&#8217;s been compromised.</p>
<blockquote class="tip"><p><strong>TIP:</strong> Always think twice before giving an app access to your account. Do your friends use it? Have they had problems? When in doubt, Google the app. See if it&#8217;s legitimate <em>before</em> you click allow.</p></blockquote>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://socialthreat.com/2010/03/08/hundreds-of-twitter-accounts-sending-out-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Say goodbye to your email, Tweeps!</title>
		<link>http://socialthreat.com/2010/03/04/say-goodbye-to-your-email-tweeps/</link>
		<comments>http://socialthreat.com/2010/03/04/say-goodbye-to-your-email-tweeps/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 13:30:25 +0000</pubDate>
		<dc:creator>Davezilla</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Koobface]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://socialthreat.com/?p=226</guid>
		<description><![CDATA[
			
				
			
		
Spammers harvesting emails from Twitter in real time!
As if you didn&#8217;t have enough things to worry your pretty heads about, spammers have figured out a simple email harvesting trick using Twitter. This is too easy. Straightforward queries for tweets containing, &#8220;gmail.com&#8221;, &#8220;email me at&#8221;, &#8220;contact me at&#8221; etc. reveal thousands of tweets that can be 


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F04%2Fsay-goodbye-to-your-email-tweeps%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F03%2F04%2Fsay-goodbye-to-your-email-tweeps%2F&amp;style=normal&amp;service=bit.ly&amp;hashtags=botnet,Koobface,spam,Twitter" height="61" width="50" /><br />
			</a>
		</div>
<h3>Spammers harvesting emails from Twitter in real time!</h3>
<p>As if you didn&#8217;t have enough things to worry your pretty heads about, spammers have figured out a <a href="http://www.webpronews.com/topnews/2009/05/11/spammers-may-have-another-trick-in-twitter">simple email harvesting trick using Twitter</a>. This is too easy. Straightforward queries for tweets containing, &#8220;gmail.com&#8221;, &#8220;email me at&#8221;, &#8220;contact me at&#8221; etc. reveal thousands of tweets that can be quickly scraped and harvested with a script. </p>
<blockquote class="tip"><p><strong>TIP:</strong> <strong>Never</strong> reveal your email openly on Twitter. DM only!</p></blockquote>
<h3>Attackers, like marketers, are targeting brands better</h3>
<p>I work in an ad agency, so I can tell you firsthand, marketers are getting damn good at targeting niche audiences and individuals. Unfortunately, <a href="http://www.darkreading.com/vulnerability_management/security/antivirus/showArticle.jhtml?articleID=223100622">so are online criminals</a>. According to <a href="http://www.cyveillance.com/web/forms/request.asp?getFile=116">Cyveillance&#8217;s 2009 Cyber Intelligence report</a> [PDF]:</p>
<blockquote><p>&#8220;Cyveillance determined that during the second half of 2009, 399 brands were first-time targets of phishing attacks, nearly double the amount of first-time targets than in the first half of the year. Averaging more than 36,000 confirmed, unique attacks per month in the same period of 2009, phishing attacks continue to succeed, the report says.&#8221;</p></blockquote>
<h3>Points for style</h3>
<p>While the Koobface gang (responsible for the <a href="http://blogs.zdnet.com/security/?p=5452">Koobface botnet and several online pranks</a>) may be somewhat nasty, you have to give them points for style and humor.</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://socialthreat.com/2010/03/04/say-goodbye-to-your-email-tweeps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Let&#8217;s Talk About Passwords</title>
		<link>http://socialthreat.com/2010/02/26/lets-talk-about-passwords/</link>
		<comments>http://socialthreat.com/2010/02/26/lets-talk-about-passwords/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 13:00:50 +0000</pubDate>
		<dc:creator>Davezilla</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips and Tutorials]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://socialthreat.com/?p=134</guid>
		<description><![CDATA[
			
				
			
		
Here&#8217;s another good take on the Twitter &#8220;Is this you lol&#8221; Phishing scam. I really like that author, Graham Cluley reminds readers to use better passwords. People. This is basic and yet 33% of you use the same password everywhere. This is ludicrous. 
Would you pin your child&#8217;s social security number to their jacket and 


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F02%2F26%2Flets-talk-about-passwords%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F02%2F26%2Flets-talk-about-passwords%2F&amp;style=normal&amp;service=bit.ly&amp;hashtags=passwords,Twitter,WordPress" height="61" width="50" /><br />
			</a>
		</div>
<p>Here&#8217;s another good take on the <a href="http://www.darkreading.com/blog/archives/2010/02/twitter_phishin.html">Twitter &#8220;Is this you lol&#8221; Phishing scam</a>. I really like that author, Graham Cluley reminds readers to use better passwords. People. This is basic and yet 33% of you use the same password everywhere. This is ludicrous. </p>
<p>Would you pin your child&#8217;s social security number to their jacket and send them to school? Of course not! But you&#8217;ll use the same password because you can&#8217;t be bothered to spend 30 seconds to think of a new one. I mean, that&#8217;s 30 seconds less you would get to play Farmville, god forbid.</p>
<p>But I digress… Let&#8217;s be constructive here. Passwords. There is nothing more critical to the security of your basic identity than having a set of good passwords to use. I know what&#8217;s running through your head right now. &#8220;I know, I know should do that, but I just can&#8217;t remember more than one and I know enough not to tape it under my keyboard.&#8221; Congratulations. You&#8217;re half way to recovery. Now you just need some tools.</p>
<p>Unless you have a truly random brain, you need to use a <strong>password generator</strong>. There are several free ones. Go use these ones now.</p>
<ol>
<li><a href="http://strongpasswordgenerator.com/">Strong Password Generator</a> is one of my favorites. You can choose the number of password characters (please don&#8217;t choose fewer than 12), whether or not to include symbols (yes, please!) and it even gives mnemonic hints to help you recall the password, despite it being quite random.</li>
<li>From <a href="http://www.goodpassword.com/">Bytes Interactive</a> comes two password generators. One creates passwords similar to Strong Password Generator with several options, the other generator creates 1337 passwords (LEET) which are based on a phrase you can recall. They also have a secure server.</li>
<li><a href="http://www.randpass.com/advanced.html">RandPass</a> has been online forever and generates very good passwords. What I like about them is the ability to generate large batches of passwords at once.</li>
</ol>
<p>You also need some place to store passwords, but no, written down on paper is for chumps who deserve to be robbed blind. Do it right. Use a password database. Here are some of my favorites:</p>
<ol>
<li><a href="http://agilewebsolutions.com/products/1Password">1Password</a>. This costs $40, but isn&#8217;t your identity worth it? 1Password can also generate them for you and has a 100% moneyback guarantee. It also comes as an iPhone app. Mac only</li>
<li><a href="http://www.onepassword.com/">OnePassword</a> is free. It integrates into Internet Explorer as a toolbar and has many of the features of 1Password.</li>
<li>How about your blog? A great plugin by Marcel Bokhorst exists for WordPress, called <a href="http://blog.bokhorst.biz/2200/computers-en-internet/wordpress-plugin-one-time-password/">One-Time Password</a>. As the name implies, it generates password logins for WordPress that can only be used one time, preventing password theft. Outstanding plugin.</li>
</ol>
<p>Hope these tips help! Do <em>you</em> know of any good password generators or password databases I didn&#8217;t mention? Let us know in the comments.</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://socialthreat.com/2010/02/26/lets-talk-about-passwords/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>A new phishing scam on Twitter?</title>
		<link>http://socialthreat.com/2010/02/22/a-new-phishing-scam-on-twitter/</link>
		<comments>http://socialthreat.com/2010/02/22/a-new-phishing-scam-on-twitter/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 18:56:30 +0000</pubDate>
		<dc:creator>Davezilla</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Scam]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://socialthreat.com/?p=35</guid>
		<description><![CDATA[
			
				
			
		
From Mashable today:
&#8220;A Twitter phishing attack is spreading rapidly today, attempting to obtain Twitter logins via Direct Messages. If you receive a message reading “lol, is this you”, and linking to a site called “bzpharma”, do not click the link.&#8221;
Phishing scams are on the rise and Twitter and Facebook will likely bear the brunt of 


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F02%2F22%2Fa-new-phishing-scam-on-twitter%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fsocialthreat.com%2F2010%2F02%2F22%2Fa-new-phishing-scam-on-twitter%2F&amp;style=normal&amp;service=bit.ly&amp;hashtags=Facebook,Phishing,Scam,Twitter" height="61" width="50" /><br />
			</a>
		</div>
<p>From <a href="http://mashable.com/2010/02/20/twitter-phishing-attack/">Mashable</a> today:</p>
<blockquote><p>&#8220;A Twitter phishing attack is spreading rapidly today, attempting to obtain Twitter logins via Direct Messages. If you receive a message reading “lol, is this you”, and linking to a site called “bzpharma”, do not click the link.&#8221;</p></blockquote>
<p>Phishing scams are on the rise and Twitter and Facebook will likely bear the brunt of them. Please, always check the links first. There are a few ways to do this:</p>
<ol>
<li>Always let your mouse hover over the link before clicking it. This way, you can see where the link is going before you click on it. If it&#8217;s a pharmaceutical site, and you&#8217;re not in the healthcare profession, it&#8217;s probably a scam.</li>
<li>On the Firefox and Chrome browsers, you can install a handy plugin called, <a href="https://addons.mozilla.org/en-US/firefox/addon/10297">Bit.ly Preview</a>. This plugin shows the full URL of shortened links on Twitter. While not all links are shortened using Bit.ly, most are, and Bit.ly is the default URL shortener of Twitter.</li>
</ol>
<p>Have you encountered any phishing scams on Twitter or Facebook? How did you resolve them?</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://socialthreat.com/2010/02/22/a-new-phishing-scam-on-twitter/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

