Twitter API weak link for worm attacks
Unless Twitter does something about hackers abusing its API, worm attacks are likely to continue.

A security researcher has suggested Twitter will be unable to stop worm attacks as long as hackers keep taking advantage of its API (Application Programming Interface).
Aviv Raff, FraudAction Research lab manager at RSA, said on his blog that even if Twitter hired the best security engineer to fix all vulnerabilities, the Twitter API would be the weak link allowing the creation of new worms.
The API is, according to Twitter, a defined way for a program to accomplish a task, which usually means retrieving or modifying data.
It said: "We provide an API method for just about every feature you can see on our website. Programmers use the Twitter API to make applications, websites, widgets, and other projects that interact with twitter."
"Programs talk to Twitter API over HTTP, the same protocol that your browser uses to visit and interact with web pages," it added.
Many third party applications use Twitter API, and Raff warned that it only took a single vulnerability in an app to trigger another Twitter worm.
Raff used the example of twitpic.com, which had a cross-scripting flaw that could be used to hijack user accounts, but could have spread due to the Twitter API.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He said: "Because twitpic.com also uses the Twitter API to automatically send twits [tweets] on behalf of the user, whenever the user uploads a picture or comments on another user's picture, it can also be easily used to create a Twitter worm."
This particular flaw has now been fixed, but Raff said it was just one example of the many services and applications that used the Twitter API and were potentially vulnerable.
Twitter has suffered several high-profile security incidents this year, while 2009 is turning out to be the year of the worm attack.
Twitter did not reply to our request for comment at the time of publishing.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Who owns the data used to train AI?
Analysis Elon Musk says he owns it – but Twitter’s terms and conditions suggest otherwise
By James O'Malley
-
Critical capabilities for full Life Cycle API Management
Whitepaper Software engineering leaders should use this research to assess and compare the capabilities of 17 products across five use cases.
By ITPro
-
Magic Quadrant for Full Life Cycle API Management
Whitepaper Assessing vendors in the fast-evolving full life cycle API management market to help software engineering leaders pick the right one
By ITPro
-
OpenAI launches ChatGPT API for businesses at competitive price
News Developers can now implement the popular AI model within their apps using a few lines of code
By Rory Bathgate
-
Elon Musk confirms Twitter CEO resignation, allegations of investor influence raised
News Questions have surfaced over whether Musk hid the true reason why he was being ousted as Twitter CEO behind a poll in which the majority of users voted for his resignation
By Ross Kelly
-
Businesses to receive unique Twitter verification badge in platform overhaul
News There will be new verification systems for businesses, governments, and individuals - each receiving differently coloured checkmarks
By Connor Jones
-
Ex-Twitter tech lead says platform's infrastructure can sustain engineering layoffs
News Barring major changes the platform contains the automated systems to keep it afloat, but cuts could weaken failsafes further
By Rory Bathgate
-
‘Hardcore’ Musk decimates Twitter staff benefits, mandates weekly code reviews
News The new plans from the CEO have been revealed through a series of leaked internal memos
By Connor Jones