[nsp-sec] Twitter under attack?

Scott A. McIntyre scott at xs4all.net
Thu Aug 6 11:49:33 EDT 2009


On Aug 6, 2009, at 16:56 , David Freedman wrote:

> ----------- nsp-security Confidential --------
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> "Ongoing denial-of-service attack 6 minutes ago
> We are defending against a denial-of-service attack, and will update
> status again shortly." - http://status.twitter.com
>
> Anybody have contacts there who may need our help?

At the time this started I noticed a large flood of emails through our  
network which were like:

---
Helo.
Visit my blog!

hxxp:// twitter .com/cyxymu

Thanks for looking my Blog.

---
Regards
mailto:cyxymu at gmail.com
---

Spaces added by me.  Also seen:

---
hi.
Important message: Watch for ya!

hxxp:// cyxymu1. livejournal.com

Thanks for looking my Blog.

---
Regards
mailto:cyxymu at gmail.com
---

Maybe a coincidence, maybe not.  I see a lot of 80/tcp syn and 443/tcp  
syn heading there, but I have no idea if that's normal and just due to  
Twits not being able to talk to the mothership or what...

Scott A. McIntyre
XS4ALL





More information about the nsp-security mailing list