55,000 Twitter passwords leaked
airdemon.net
airdemon.net
All their bios sound like bot-generated text, they all have suspiciously similar passwords that look auto-generated, and none of them seem to have much to say.
On a hunch, I logged in to a few of those accounts and saw that they all had messages asking them to confirm their email addresses, as they had not done so yet.
This is probably not a "leak," but some spammer's list of fake accounts.
Ok, since I like to randomly speculate about various facts, consider the following, what if this was a white hat operation? We have seen that folks who uncover botnets are in a weird place because if they take them out they can be accused of violating the CFA but if they leave them in place, the world stays sucky. So what to do? A creative missive to not take them out?
A white hat can 'leak' all of the spam accounts, which engages Twitter's customer relations team, which disables all the accounts because they might be 'compromised' and sends an email to the owner to change their password. Except they are spam accounts and don't have real emails so the emails go into the bit bucket and 55,000 spam accounts go dark. I realize that is a lot of construction.
Well if you do anything automatically then you put yourself at risk for people bullying other legit users by accusing them of spamming. Since real users tweet all sorts of bad things when you accidentally ban them, you want zero false positives, so you have a fairly heavy weight policy.
So if the policy takes an hour per account, reports of 55,000 would be really hard to do. However, if you release the passwords of them into the 'wild' then all Twitter has to do is 'prevent further abuse' which is a password reset and mass mailing.
Again, its pure speculation on this leak, the problems with acting on internet reported abuse is one that I got to see first hand at Google when I was there (people get reported as spammers, accounts get disabled, tempers flare, nobody is happy, it is a really hard problem.)
Why do people do this? Or rather, why do people do this and then admit to it in public forums?
This is unethical and probably illegal.
Unethical and probably illegal. You just admitted to logging into someone else's account without their permission. At the very least you probably violated Twitter's terms.
(and even in the US it is much more nuanced. logging in and doing nothing with a public username and password is really in the grey area).
The only restriction on US law is how hard we want to push other governments to enforce them.
is that a crime?
I think this is from a third-party service, back when OAuth was not common, or maybe from a fake service someone created just to steal passwords.. There are many accounts that couldn't possibily be created on twitter:
12:12
A:A
ANJO_SO@RES .COM:
917048566:2252It seems the usernames are quite random as well. So far, not much lost then :)
I am fairly worried by the security policy at Twitter.
For example, I have a friend who had his Twitter account hacked. As an experiment, he deactivated the account, but did not change the password. Whoever had the password logged into the hacked account and reactivated it. When he received the email of the reactivation, there was no "If you did not initiate this, click here" option.
edit: formatting
10% of accounts are active (daily/weeekly participation)
1% of accounts are "whales" (provide high level to the service).
~15-50% of accounts are some-time users.
~25-50% of accounts are one-time users (registered but never used)
If your service is sufficiently old, call it 5-10 years ...
~25-50% of accounts are expired / no longer reachable (usually the contact email/phone is no longer valid).
Active spammers don't have to be a high level of the service to be disruptive, but can be anywhere from 1-25%, mostly depending on how effective you are at rooting them out.
Very, very rough, and no, I don't have a particularly good basis to back these up other than the first 2-3 values.
If this really is a list of spammer accounts, the ones that look like real accounts are probably stolen from legit users to be used for spamming.
EDIT: They gained 70k followers in the past two days alone[2].
EDIT 2: Their tweets have all disappeared since posting this comment.
CONCLUSION: Automatically generated accounts, profiles, and tweets. These accounts are used for services that provide paid followers and retweets. It's actually pretty interesting stuff if you look at the automatically generated "Twitter Ipsum" that is their profile descriptions and how they randomly pick quotes from famous people to tweet.
Anyone know anything more about this? Are there companies overtly selling followers?
Looks like either some kind of weird social hack/club or I don't know what..
This account has close to 1M followers, and appears to be in that same network or loop of spammy follower-harvesting group..
Look at Swagstro's follower list [1], and Cmd/Ctrl-F for "holic", "fanatic", "introvert", "bacon", "wannabe". Almost all of the accounts are simply randomly generating the Lorem Ipsum of Twitter descriptions.
Some big weekly jumps in March (~50k) and April (~30k).
Magic SEO? Or the next JB? Something to do with clothing?
The domain "swagst.ro" is currently available for US$37 per year...
[1] https://twitter.com/#!/Rene (Verified Twitter Account)
---
... natymattyoly_souza@hotmail.com:123456789321 < probably guessed numbers until the system said it wasn't "too obvious"
...
anderson_andimdim@hotmail.com:159753100 < physical numpad pattern, "X" + 100
...
danielmarianosantana@hotmail.com:euamominhamae < "i love my mom" in portuguese... Twitter blocks "iloveyou" as it's a really common password, but this seems similar
joaovitor.bragaferreira@hotmail.com:africadosul
rafacavali82@hotmail.com:molestia
girlangts@hotmail.com:tei,xei,ra,
theublack10@hotmail.com:matheussofia
r_gto33@hotmail.com:picaxura
There are many others that may be autogenerated, but I think we can rule out the idea that most or all of them are. The common patterns are probably just because humans are bad at this "make up a secret that no one else makes up" game.
curl http://pastebin.com/raw.php?i=Kc9ng18h > twitterpw.txt
curl http://pastebin.com/raw.php?i=vCMndK2L >> twitterpw.txt
curl http://pastebin.com/raw.php?i=JdQkuYwG >> twitterpw.txt
curl http://pastebin.com/raw.php?i=fw43srjY >> twitterpw.txt
curl http://pastebin.com/raw.php?i=jv4LBjPX >> twitterpw.txt curl "http://pastebin.com/raw.php?i={Kc9ng18h,vCMndK2L,JdQkuYwG,fw43srjY,jv4LBjPX}" > twitterpw.txt
Then:
$ wc -l twitterpw.txt
58978 twitterpw.txt
$ sort -u twitterpw.txt | wc -l
37001Lots of dupes in there.
curl "http://pastebin.com/raw.php?i={Kc9ng18h,vCMndK2L,JdQkuYwG,fw43srjY,jv4LBjPX}" | sort -u > twitterpw.txtHrm ... No, but process substitution does:
curl "http://pastebin.com/raw.php?i={Kc9ng18h,vCMndK2L,JdQkuYwG,fw43srjY,jv4LBjPX}" | tee >(sort -u >twitterpw.txt) | wc -l
[1/5]: http://pastebin.com/raw.php?i=Kc9ng18h --> <stdout>
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 261k 0 261k 0 0 788k 0 --:--:-- --:--:-- --:--:-- 953k
[2/5]: http://pastebin.com/raw.php?i=vCMndK2L --> <stdout>
100 434k 0 434k 0 0 1630k 0 --:--:-- --:--:-- --:--:-- 1630k
[3/5]: http://pastebin.com/raw.php?i=JdQkuYwG --> <stdout>
100 349k 0 349k 0 0 1526k 0 --:--:-- --:--:-- --:--:-- 7441k
[4/5]: http://pastebin.com/raw.php?i=fw43srjY --> <stdout>
100 367k 0 367k 0 0 897k 0 --:--:-- --:--:-- --:--:-- 897k
[5/5]: http://pastebin.com/raw.php?i=jv4LBjPX --> <stdout>
100 291k 0 291k 0 0 1638k 0 --:--:-- --:--:-- --:--:-- 1638k
58978
And what did we actually output? $ wc -l twitterpw.txt
37001 twitterpw.txt for k in Kc9ng18h vCMndK2L JdQkuYwG fw43srjY jv4LBjPX; do curl http://pastebin.com/raw.php?i=$k >> twitterpw.txt; done66 - No password (ie null)
580 - had the password "315475"
492 - had password "123456"
187 - had password "123456789"
68 - had password "102030"
62 - had password "123"
52 - had password "12345"
44 - had password "1234"
29 - had password "101010"
35% were numeric/number only passwords. There were many that were a variation of 123...
The rest appear to be a mixture but first names are popular. I haven't tried, but would assume many of these would be the same passwords for the registered email (username).
The day someone comes up with an alternative to passwords it will be a great day!
Edit: [1] 34k unique accounts, I must have deleted duplicate usernames/accounts.
See this forum thread: http://psx-scene.com/forums/f195/twitter-1200-follwer-hack-v... which links to this pastebin page which contains a bunch of users all with that password http://pastebin.com/0hcDigvU
So maybe random generated by twitter or spam accounts?
Edit: Appear to be closed or suspended accounts.
Definitely looks like it was a large-scale spam operation that was hacked and not twitter itself.
I just edited the title to try to reflect the lesser impact of the leak.
But many of them have exactly the kind of password you would expect humans to have. Maybe those were accounts that were stolen (phished?) and added to the spam operation, but they certainly seem like human-generated (i.e. mostly bad, but more importantly, without an obvious pattern) passwords to me.
If this was twitter that got hacked, it implies that they're storing passwords in plain text.
That news is or should be a Big Deal.
58978 accounts listed, 34064 unique account/passwords
25069 accounts by email 8995 accounts by usernames
Most accounts by email:
hotmail.com @ 15598
yahoo.com.br @ 2375
gmail.com @ 2148
bol.com.br @ 1031
uol.com.br @ 695
A lot of misspellings for domain names.
Unless of course as other people pointed out its just the same person who registered a large portion of these accounts.
Fair point.
$ wc -l twitterpw.txt
58924 twitterpw.txt
$ sort twitterpw.txt | uniq | wc -l
36997I don't think that's very fair.
> "All they need to do is to add a password strength checker during signup while changing passwords. And guide the users to create a strong password. That could save a lot of users frustration."
Right...
Assuming Twitter does this kind of obfuscation, then all the password couldn't be retrieved from Twitter directly and hence no blaim on Twitter side.
Assuming Twitter does not obfuscate the password, why then nobody mentioning this? In such a case Twitter made a beginner failure and this should be somehow pointed out, I think. I just remember the case about one dating-site, which did that and it was more or less lynched for this by the community.
There were ~55k user:passwd leaked.
And while a large subset may come from specific regions, it's hard to say if they all do.
But we already have a connection between all accounts, (obviously) they were all hacked and released together. (Pretty strong connection).
So then the number might allude to an effort of some scale for some unknown reason.
Currently and besides the legitimate users of the accounts, only one entity has "taken damage" from this "leak". Twitter
So anyone care to continue this line of thought?
midstreamEdit: NYtimes is saying it's a retaliation hack.
If only it was that easy to prevent account stealing.
which leads to:
http://www.twitteraccountcreator.net/services/index.html
Edit: Why am I being down voted? The links above seem relevant to me.
The "Planex" account is simply a pastebin spammer. If you visit http://pastebin.com/u/Planex you can see all the things this account has pastebin'd. Just because they had a spam pastebin related to a Twitter service does not make it related to the other 5 pages.
Maybe this will be helpful for some people.
Edit: There are twitter accounts to match the usernames - the few I checked were bots. I won't test the passwords.
The passwords are far too complex based on previous password dumps I've seen.
Did anyone actually try any of these? None of them work.(Correct me if I'm wrong -- I didn't try them _all_)
Edit: Nevermind... they seem to be passwords, not hashes. They look randomish though. Likely computer generated.
I recommend 1password for managing passwords so that issues like this are easier to manage and so that I do not use the same few passwords everywhere.
"'The micro blogging platform is aware of this hack and was taking necessary actions to save those people’s account from malicious activity', said a Twitter insider."
At first my reaction to the story was "like I give a tweet!" What are they going to do, tweet something inane? Um... that's kind of the point of the whole service, isn't it?
But then I remembered the true vulnerability with leaked usernames/passwords: people use the same ones across sites.
These same people would never change their username/password combo on ANOTHER site due to prompting ont he Twitter site. They just can't read and follow directions like that. (If they could they probably wouldn't have the same username/pd combo).
So, I think that: "'The micro blogging platform is aware of this hack and was taking necessary actions to save those people’s account from malicious activity', said a Twitter insider." is asking the impossible.
The only malicious activity is on the users' other, real, non-SMS-length-message-broadcasting-to-the-whole-world accounts... (email, facebook, etc)