Published on Maximum PC (http://www.maximumpc.com)


Twitter Users Hope Cure for Mikeyy Worm Lasts
Created 04/14/2009 - 3:47pm

Maximum IT
    • Novell: It's Tough to Make Money with Open Source, "Keep it Proprietary"
    • Dell's 3Q Sales and Profits Fall Flat
    • Kaboom! Data Firm Makes Its Point by Blowing Up a Server

    Sponsored
SEE MORE MAXIMUM IT
News
  • Microsoft Offers to Pay News Corp to "De-List" From Google
  • Intel Wants to put a Chip in Your Brain
  • Magic Mouse Drivers For Windows Emerge
  • Is Apple Using a Technicality to Avoid 3G License Fees?
  • Roadmap Slide Pegs Windows 8 for 2012
SEE MORE NEWS
News

Twitter Users Hope Cure for Mikeyy Worm Lasts

Posted 04/14/09 at 06:47:08 PM  by Mark Edward Soper

comment Commentsprint Printemail EmailDeliciousDiggStumbleUponRedditFacebookSlashdot

Over Easter weekend, Twitter users were besieged by the Mikeyy worm

Over Easter weekend, many Twitter fans were getting worms instead of finding Easter Eggs, as the developer of a rival microblogging site (StalkDaily), one 17-year-old Michael "Mikeyy" Mooney, was busy drawing Twitter users to his site by using the so-called "Mikeyy" or "StalkDaily" worm to infect links and Twitter profiles. According to PCWorld and the Twitter status page, the infection has now been brought under control. But inquiring minds want to know, "what happened?" and "how can we stop a future attack?"

Doing a Google search for "Mikeyy" or "TwitterWorm" isn't the best way to find out, though, as the F-Secure security blog points out that fake news sites are being used to infect curious searchers with (unrelated) malware. So what really happened?

Mikeyy/StalkDaily used XSS (Cross-Site Scripting) and CSRF (Cross Site Request Forgery) attacks (we've discussed XSS a number of times here at MaximumPC.com). Website developer and Twitter expert Lynne Pope offers an excellent analysis of how the Mikeyy/StalkDaily attacks worked, and how you can protect yourself from similar exploits in the future:

The very first thing you must do to protect yourself is this - do not browse to any sites while logged on to another site. Leaving authentication cookies exposed is dangerous. Log off, then navigate away.

Ms. Pope also recommends:

  • Firefox fans should use NoScript to prevent scripts from running without explicit permission.
  • Use the Hosts file to block domains pointed to by malware.
  • Use tools available at LongURL.org to determine where short URLs are actually pointing to (Mikeyy/StalkDaily used bit.ly and tinyurl.com to conceal the actual websites used for spreading the worm).

Were you affected by the Mikeyy/StalkDaily worm? Hit Comment and tell us your war stories.

Twitter logo courtesy of a MESS of commentary. 
COMMENTS:0
TAGS: Security, twitter, malware, web 2.0, XSS, exploit, vulnerability, worm, JavaScript, web browser, Mikeyy, StalkDaily, Lynn Pope
COMMENTS
  • Login or register to post comments
  • Technology News

  • Computer Cooling Fans

  • Computer Cases

  • PC Game Controllers

  • PC Games

  • Computer Hardware

  • Headphones

  • MP3 Players

  • Stream Video

  • Computer Mouse

  • Monitors

  • Motherboards

  • NAS Storage

  • Networking

  • Laptop Computers

  • DVD Burner

  • Digital Cameras

  • Portable Storage

  • Computer Accessories

  • Smartphone

  • Antivirus Software

  • Sound Cards

  • Speakers

  • Computer Systems

  • Thumb Drives

  • Video Cameras

  • Video Card Reviews

  • Water Cooling

  • Gadgets

  • Keyboards
  • Contact Us
  • Advertising
  • Privacy Policy
  • Terms & Conditions
  • RSS Feeds
  • TechBlips
  • PCHardwareBlips
  • Site Map
  • Customer Service
Future © 2009 Future US, Inc. All Rights Reserved.

Source URL: http://www.maximumpc.com/article/news/twitter_users_hope_cure_mikeyy_worm_lasts

Links:
[1] http://www.maximumpc.com/user/marcus_soperus
[2] http://adjix.com/af5t
[3] http://www.pcworld.com/article/163054/twitter_worm_a_closer_look_at_what_happened.html
[4] http://status.twitter.com/post/95332007/update-on-stalkdaily-com-worm
[5] http://www.f-secure.com/weblog/archives/00001657.html
[6] http://www.maximumpc.com/tags/xss
[7] http://lynnepope.net/stalkdaily-twitter-xss-lessons-learned
[8] https://addons.mozilla.org/en-US/firefox/addon/722
[9] http://longurl.org/tools
[10] http://messofcommentary.wordpress.com/
[11] http://www.maximumpc.com/article/googles_in_the_xss_crosshairs_and_so_are_you
[12] http://www.maximumpc.com/article/news/beware_twitter_us_intelligence_labels_tweets_a_terrorist_tool
[13] http://www.maximumpc.com/article/news/hacker_targets_twitter_celebrities_concisely_slandered