funsec mailing list archives

Twitter "spam account" protection?


From: "Rob, grandpa of Ryan, Trevor, Devon & Hannah" <rMslade () shaw ca>
Date: Sat, 11 Jul 2009 12:20:18 -0800

Anybody know how to keep Twitter "spam accounts" from following you, while 
still allowing people to access your updates?

This is a fairly specific question, so it's for those who have been working with 
Twitter extensively.

Twitter allows people to follow the updates, or "tweets," that you post on the 
system.  It also allows people to "follow" you, in order to get your 
postings/updates automatically in various ways.  If someone looks at your Twitter 
profile, they will be able to see the list of people who are "following" you.

Spammers have decided to take advantage of this in order to get in on a kind of 
"friend of a friend" system of advertising.  They create accounts and use them to 
advertise.  (Usually porn, of course.)  An account with a name like 
RavishingAngela079876 (and a picture with sufficient amounts of fleshtones in it) 
will be created.  Sometimes this will be used to post with keywords and hashtags 
that are currently high on the search list.  Very often, however, the account will 
simply be created with a single "update" on it, pointing to a porn site.  Then 
RavishingAngela079876 will "follow" me, and about 3619 other people.  Anyone 
interested in my posts might be interested in people who "follow" me, so they 
might look at my list of "followers," find RavishingAngela079876, and (since the 
update on "her" account uses a redirector) the porn site gets another clickthough.

Twitter does have a security provision.  I can "Protect my updates."  
Unfortunately, if I do that, nobody can see my postings unless I specifically and 
individually allow them to.  And it's binary: protect your account, or not.  So it's 
not a good choice if you are trying to create a resource for public use.

At the moment, every few days I manually check my "followers" for those who 
probably aren't terribly interested in security or book reviews.  But it's a bit of a 
pain.

Anybody with more experience in Twitter know if there are other options?

======================  (quote inserted randomly by Pegasus Mailer)
rslade () vcn bc ca     slade () victoria tc ca     rslade () computercrime org
I'm never going to be famous. My name will never be writ large on
the roster of Those Who Do Things. I don't do any thing. Not one
single thing. I used to bite my nails, but I don't even do that
any more.         - famous American reviewer and wit, Dorothy Parker
http://victoria.tc.ca/techrev/rms.htm 
http://blog.isc2.org/isc2_blog/slade/index.html http://twitter.com/rslade
http://blogs.securiteam.com/index.php/archives/author/p1/
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: