{"id":454983,"date":"2022-08-02T10:52:21","date_gmt":"2022-08-02T08:52:21","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=454983"},"modified":"2022-08-02T10:53:14","modified_gmt":"2022-08-02T08:53:14","slug":"twitter-accounts-vulnerable-to-hijacking-after-3200-apps-found-leaking-api-keys","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/454983-twitter-accounts-vulnerable-to-hijacking-after-3200-apps-found-leaking-api-keys.html","title":{"rendered":"Twitter accounts vulnerable to hijacking after 3,200 apps found leaking API keys"},"content":{"rendered":"<p>CloudSEK researchers have <strong><a href=\"https:\/\/cloudsek.com\/whitepapers_reports\/how-leaked-twitter-api-keys-can-be-used-to-build-a-bot-army\/\" target=\"_blank\" rel=\"noopener\">found<\/a><\/strong> 3,207 mobile applications leaking valid Twitter application programming interface (API) keys and tokens, allowing attackers to hijack compromised accounts.<\/p>\n<p>The affected applications include banking apps, event loggers, city transportation companions, radio tuners, book readers and GPS cycling trackers, BleepingComputer <strong><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/over-3-200-apps-leak-twitter-api-keys-some-allowing-account-hijacks\/\" target=\"_blank\" rel=\"noopener\">reported<\/a><\/strong>.<\/p>\n<p>CloudSEK reportedly disclosed the vulnerabilities to the relevant companies a month ago, but most have not addressed the issues.<\/p>\n<p>With a hijacked account, attackers can read direct messages, access account settings, remove followers, retweet, like, and delete posts.<\/p>\n<p>By hijacking verified accounts, attackers can create bot armies to run large-scale malware campaigns and spread misinformation.<\/p>\n<p>These bot armies are also often used to automate phishing and cryptocurrency scams.<\/p>\n<p>The researchers said attackers use verified Twitter accounts to lend credence to the scams.<\/p>\n<p>CloudSEK\u2019s security search engine for mobile applications, BeVigil, discovered that 3,207 applications were leaking valid Consumer Keys and Consumer Secrets for the Twitter API.<\/p>\n<p>The Twitter API allows developers to integrate their applications with Twitter\u2019s core functionalities.<\/p>\n<p>\u201c[Twitter\u2019s API] ensures that developers can come up with their own unique ways of embedding Twitter\u2019s data and functionality in their applications,\u201d CloudSEK said.<\/p>\n<p>The researchers said the vulnerability exists because developers save the API keys and tokens within the mobile application.<\/p>\n<p>\u201cSometimes, these credentials are not removed before deploying it in the production environment. Once the app gets uploaded to the play store, the API secrets are there for anyone to access.\u201d<\/p>\n<p>\u201cSome of the leaked credentials belonged to verified Twitter accounts,\u201d CloudSEK said.<\/p>\n<p>CloudSEK has recommended that developers follow secure coding and deployment processes like hiding and rotating authentication keys and ensuring accurate versioning.<\/p>\n<p>\u201cIt is imperative that API keys are not directly embedded in the code,\u201d the researchers said.<\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2022\/08\/How-Leaked-Twitter-API-Keys-Can-be-Used-to-Build-a-Bot-Army.pdf\" width=\"100%;\" height=\"700;\">How-Leaked-Twitter-API-Keys-Can-be-Used-to-Build-a-Bot-Army<\/iframe><\/p>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/454350-dangerous-samba-bug-could-lock-administrators-out-of-their-domains.html\">Dangerous Samba bug could lock administrators out of their domains<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>CloudSEK researchers have found a massive amount of mobile applications leaking Twitter API keys, leaving users vulnerable to exploitation.<\/p>\n","protected":false},"author":341094,"featured_media":454985,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[65978,80333,80331,405],"class_list":["post-454983","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-application-programming-interface-api","tag-bevigil","tag-cloudsek","tag-twitter"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/454983"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341094"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=454983"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/454983\/revisions"}],"predecessor-version":[{"id":455001,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/454983\/revisions\/455001"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/454985"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=454983"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=454983"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=454983"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}