Sunday, April 12, 2009

Creator of StalkDaily twitter worm -> a 17 y/old kid

As many people have become aware of, a Twiter worm broke loose on Saturday, April 11th, which became known as the "StalkDaily Worm." The creator of website StalkDaily.com, 17 year old Mikeyy Mooney, came clean Saturday evening, in an interview with BNO News. He stated that he created the worm simply out of boredom, a common theme in malicious computer code. He admitted to having an interest in finding vulnerabilities on sites. He did in fact bring light to a Cross Site Scripting (XSS) flaw, that could have been used much more maliciously. The kid did a service by letting Twitter see the problem in their code, and he got some free advertising for his own website in the process. He says that the code did not steal any sensitive data, or passwords. Examining the code seemed to support his claim, the script grabbed the user's twitter cookies to make use of Twitter's API, but no computers were compromised, no accounts were used to steal financial information, no one's computer was sending cryptic communications to missile silos.
He started by making several accounts, with the worm code embedded into the Bio section on the profiles, the fact this was allowed was the XSS bug he brought to light. Unlike other worms, where you are safe if you don't click suspicious links, this worm worked by just viewing the infected profile. The script waited for three seconds, before taking the user's cookies. After which, the worm would add itself into the target's Bio section, and send out Tweets linking to Mooney's site. No damage, no ruined finances, just a worm being exposed to the public.

1 comments: