Twitter Tweet Button URL randomly resolves to a .torrent file
gist.github.com
gist.github.com
Again: this is just my guess.
All S3 files by default can be distributed with torrent, if the URL is appended with ?torrent
S3 servers will act as a tracker and seeds.
I also have no idea when I'll ever use it, but still. Damn cool.
http://torrentfreak.com/twitter-bug-requires-users-to-torren...
TL;DR is Twitter uses bittorrent internally, this is probably just an error in letting an internal configuration leak to the outside world.
Chrome automatically downloaded it => http://cl.ly/image/2u3R2m3j3j1E
Is it possible someone hijacked this IP?
Edit:
1. Seems the IP belongs to a CDN (edgecast).
If users have their browsers configured to automatically start the download of any .torrent files without confirmation, twitter giving bogus .torrent is no more dangerous than $malware_site linking a .torrent. So that's not a security issue on twitter's site.
And anyway, I still fail to see how downloading a file (through bittorent or otherwise) constitutes a security breach on its own. Unless of course the bittorent client auto-executes binaries when it's done downloading, but that's just silly (and still nothing to do with twitter's security policy).
1. User configures browser to automatically start torrent downloads when a ".torrent" link is clicked
2. User clicks twitt button which leads to a torrent file
3. The file is downloaded and opened in a torrent client
At this point, one could imagine a specifically crafted torrent file which exploits some vulnerability of the torrent client to gain (say) arbitrary code execution and now the user is, to use a mild term, screwed.
This attack could be used by any malicious site, really, but it's easier to get people to click a twitt button rather than some link on some site and besides, by preforming the attack this way the attacker would infect a sizable chunk of all internet sites (any site that uses the twitt button).
When this conjecture was posted I assumed someone hijacked a CDN used by twitter and used the twitt button as an attack vector by making it redirect to a torrent file.
I'm not saying twitter is trying to infect its users or something. In all probability, it's just a configuration screw-up and not an attack but (for all we know) it could be.
The platform they developed is called Murder: https://blog.twitter.com/2010/murder-fast-datacenter-code-de...
Edit: I just browsed TC and I am getting the torrent download there too..