Posted 04/14/09 at 06:47:08 PM by Mark Edward Soper

Over Easter weekend, many Twitter fans were getting worms instead of finding Easter Eggs, as the developer of a rival microblogging site (StalkDaily), one 17-year-old Michael "Mikeyy" Mooney, was busy drawing Twitter users to his site by using the so-called "Mikeyy" or "StalkDaily" worm to infect links and Twitter profiles. According to PCWorld and the Twitter status page, the infection has now been brought under control. But inquiring minds want to know, "what happened?" and "how can we stop a future attack?"
Doing a Google search for "Mikeyy" or "TwitterWorm" isn't the best way to find out, though, as the F-Secure security blog points out that fake news sites are being used to infect curious searchers with (unrelated) malware. So what really happened?
Mikeyy/StalkDaily used XSS (Cross-Site Scripting) and CSRF (Cross Site Request Forgery) attacks (we've discussed XSS a number of times here at MaximumPC.com). Website developer and Twitter expert Lynne Pope offers an excellent analysis of how the Mikeyy/StalkDaily attacks worked, and how you can protect yourself from similar exploits in the future:
The very first thing you must do to protect yourself is this - do not browse to any sites while logged on to another site. Leaving authentication cookies exposed is dangerous. Log off, then navigate away.
Ms. Pope also recommends:
Were you affected by the Mikeyy/StalkDaily worm? Hit Comment and tell us your war stories.
Links:
[1] http://www.maximumpc.com/user/marcus_soperus
[2] http://adjix.com/af5t
[3] http://www.pcworld.com/article/163054/twitter_worm_a_closer_look_at_what_happened.html
[4] http://status.twitter.com/post/95332007/update-on-stalkdaily-com-worm
[5] http://www.f-secure.com/weblog/archives/00001657.html
[6] http://www.maximumpc.com/tags/xss
[7] http://lynnepope.net/stalkdaily-twitter-xss-lessons-learned
[8] https://addons.mozilla.org/en-US/firefox/addon/722
[9] http://longurl.org/tools
[10] http://messofcommentary.wordpress.com/
[11] http://www.maximumpc.com/article/googles_in_the_xss_crosshairs_and_so_are_you
[12] http://www.maximumpc.com/article/news/beware_twitter_us_intelligence_labels_tweets_a_terrorist_tool
[13] http://www.maximumpc.com/article/news/hacker_targets_twitter_celebrities_concisely_slandered