Twitter security hole lets you make anyone follow you

Tweet "accept username" in the web interface


10 May 2010 17:58 GMT / By Duncan Geere

A security hole has been found in Twitter that allows any user to force anyone else to follow them, without the follower giving any kind of permission at all.

By sending the word "accept" into the web interface, followed by the username of the person you want to follow you, you can tap into a defunct system that Twitter once used to operate the site. We've tested it on a dummy account and found that yes - it works, and yes - it's instant. We imagine it'll be patched out of existence rather quickly.

Still, it's a massive security hole, and there'll no doubt be legions of celebrities and big-name Twitter users up in arms about their feeds being flooded with unknown users. It's as yet unclear if it gives access to feeds that are "protected", as the following/not-following mechanism is separate from that.

Until Twitter manages to fix this problem, keep an eye on your Twitter feed to weed out any undesirables and spammers.

UPDATE: It seems that Twitter is on the case already with all Twitter users showing 0 followers and 0 following tallies. We will keep you posted.

UPDATE 2: Twitter has issued the following statement: "We identified and resolved a bug that permitted a user to “force” other users to follow them. We’re now working to rollback all abuse of the bug that took place. Follower/following numbers are currently at 0; we’re aware and this too should shortly be resolved. Update (10:18 AM PST): Of note: protected updates did not become public as a result of this bug".

Via: gizmodo.com

Full tags
Software, Online, Twitter, Social networks

share print story pdf email story

Recommended articles

Recommended articles from around the web

Loading

Best iPad 2 apps

We detail the best iPad 2 and iPad apps in the app store Which iPad app should you download?

Best new iPad apps

We detail the best iPad apps in the app store for your new Retina Display Which iPad app should you download?

Windows 8

First Look: Windows 8 Consumer Preview reviewed

The new iPad

The new iPad: Everything you need to know

Pocket-lint poll

Q. Does the Samsung Galaxy S III deliver what you hoped for?

Vote YES Vote NO

» LAST TIME
When asked Would you switch from iOS to Android? 54% said yes and 46% said no